Certificate Authority (CA) for every PKI use case.
Digital certificates are the foundation of modern IT security.
They secure communications, authenticate systems and users, and ensure the integrity of sensitive data.
People (employees, customers, business partners, etc.), electronic devices, and IT services need a digital identity to interact securely with one another. Most of these identities are represented by certificates.
OUR SOLUTION
primeID CERTIFY enables the operation of multiple PKI hierarchies on a single platform, centralizes the configuration and management of certificate policies, and provides access to detailed, optionally signed audit and transaction logs from a central location. Configuring CAs and certificate templates becomes a straightforward task. An optimized process for issuing, managing, and maintaining digital certificates simplifies and automates recurring tasks, reduces manual errors, and ensures uninterrupted operation. primeID CERTIFY is a platform-independent application that can be easily implemented in complex environments. The solution scales from a few certificates to a corporate-wide enterprise solution that issues millions of certificates.
primeID CERTIFY already supports PQC algorithms and is designed to be future-proof. This is made possible by built-in cryptoagility. Algorithms, key lengths, and certificate formats can be flexibly swapped out or operated in parallel with minimal effort. This enables early migration to hybrid or fully quantum-resistant methods without having to reconfigure existing processes or certificate inventories.
Features
primeID CERTIFY is a unified PKI platform that enables companies to manage multiple certification authorities (CAs) centrally rather than through heterogeneous, siloed solutions. The platform is designed to be future-proof and ready for post-quantum cryptography (PQC). This is made possible by built-in cryptoagility: algorithms, key lengths, and certificate formats can be flexibly exchanged or migrated with minimal effort.
primeID CERTIFY offers excellent scalability for large-scale deployments through database tier clustering and high-availability (HA) configurations.
primeID CERTIFY can be deployed as software, a container, a cloud instance, or a managed service.
primeID CERTIFY supports integrations with Active Directory (AD), Azure AD, Kubernetes, and other systems.
primeID CERTIFY is seamlessly integrated into primeID AUTOMATE Certificate Lifecycle Management.
primeID CERTIFY provides an interface for direct integration with credential management systems (CMS), such as MyID, to manage user certificates directly through the CMS.
primeID CERTIFY features direct integration with primeID VALIDATE
primeID CERTIFY is based on a trusted, CC-evaluated solution
- RFC 5280-compliant X.509 certificates and CRLs
- PKCS#10, CRMF, and SPKAC certificate requests
- PKCS#12, JKS, PEM, and PKCS#11 keystores
- EN 319 412 eIDAS-compliant certificates
- OCSP in accordance with RFC 6960 and RFC 5019
- ICAO 9303, EAC 1.11, and EAC 2.10 ePassport and eID
- RFC 6962-compliant Certificate Transparency
primeID CERTIFY supports:
Enrollment and automation protocols
ACME (RFC 8555), SCEP (RFC 8894), EST, CMP, Microsoft Autoenrollment
API protocols
REST APIs
Directory & Identity Protocols
LDAP (Active Directory and OpenLDAP) with automatic distribution of certificates and CRLs, as well as LDAP v3 compliance (RFC 4519, RFC 4524). SAML for SSO integration with existing IAM systems
Revocation & Status Protocols
OCSP, CRL, and Delta-CRL, configurable per certificate profile; Emergency CRL
Communication & Security Standards
TLS and IPsec for encrypted communication between devices; international standards such as ETSI, IEEE, and 3GPP are supported for telecommunications and IoT
primeID CERTIFY supports:
FIPS 203, ML-KEM, based on CRYSTALS-Kyber
FIPS 204, ML-DSA, based on CRYSTALS-Dilithium
FIPS 205, SLH-DSA, based on SPHINCS+
Coming soon:
FIPS 206, FN-DSA, based on FALCON
primeID CERTIFY supports all common HSM solutions:
- Thales LUNA
- Entrust nShield
- Utimaco
- AWS Cloud HSM
- Azure Key Vault Managed HSM
- All PKCS#11-compliant modules
YOUR BENEFITS
+ Future-proof PKI platform
+ Multi-tenant operation on a single platform
+ Seamless enterprise integration
+ High-performance architecture
+ Flexible deployment options
+ Foundation for compliance and Zero Trust
+ Broad coverage of use cases
+ Seamless integration with primeID AUTOMATE Certificate Lifecycle Management, primeID VALIDATE and solutions for managing SmartCards and Token
Do you have any questions or need more information?