Machine Identities
Certificate autoenrollment for servers, clients, IoT devices in the Azure cloud or on-premises via ACME, SCEP and EST.
Release is coming soon!
Servers
Auto-enroll trusted TLS certificates from a public CA or your internal CA to your web servers automatically and centrally managed via ACME.
Clients
Provide certificates for authentication or VPN to your Windows, Linux, Apple or Android devices automatically via SCEP or ACME!
IoT and OT devices
Automatically provision your Industry IoT and OT devices with mTLS authentication certificates via the modern EST protocol.
"Secardeo certPort automatically provides all types of IT machines operated and managed in the cloud or on-premises with authentication certificates ."
Avoid server downtime and lower costs!
- Automatic certificate renewal via ACME prevents from outages due to expired certificates.
- Constantly decreasing lifetimes of server TLS certificates need frequent renewals.
- Each manual certificate renewal will cause internal costs.


Enable Zero Trust network access.
- Autoenroll and -renew certificates for your clients managed by Intune or other MDM systems.
- Replace your outdated NDES by modern and extended technology for SCEP.
- Autoenroll certificates for Linux clients or Apple devices using the modern ACME protocol.
- Validate and compose certificate requests according to your policy
- Autorevoke Intune SCEP certificates or ACME certificates on request.
On-premises or in your Azure cloud.
- Deployment as an Azure Web App in your tenant assures full control over the complete service.
- Full integration with Intune for automated enrollment, management and revocation of device certificates.
- Out-of-the-box integration with SECARDEO certVault CA for issuing certificates in your Azure cloud tenant.
- Deployment in your Active Directory provides deep integration with ADCS and AD certificate templates.
- Several CA-Backends for the integration with other private or public CAs are provided.

How it works
certPort is a Web Application service for automatically enrolling certificates for servers, clients, devices, and users by standard enrollment protocols from public and private certification authorities. certEntra runs as a Web App Service in the customer's Azure cloud (tenant) or on-premises on a virtual machine and is therefore completely under the customer's own control.
Client certificates
For a secure network access strong authentication using client certificates according to IEEE 802.1x is best practice. These certificates can be requested from Windows or Linux clients or mobile devices and they can also be used for protected VPN connections.
User certificates
Certificates can be issued for a user for certificate based authentication (CBA), VPN connections or even digital Signatures (e.g. S/MIME). For the enrollment of S/MIME encryption or multipurpose certificates other TOPKI components like certEntra, certEP or certLife are recommended.
Server certificates
Server certificates are required for authentication and establishment of a secure TLS channel with the client or even a VPN server.
IoT & OT device certificates
Authentication of a huge number of IoT devices can only be handled efficiently using certificate based protocols like mTLS. This applies also to Operational Technology (OT) devices or Industry 4.0 environments.
Certificate handling and management
The received certificate requests will be validated and, together with additional request parameters, will be forwarded to the connected CA.
Certificates will be stored in the TOPKI database which can be hosted in Azure SQL, Azure Database for MySQL, MSSQL or MySQL.
certPort can be configured through a web configurator that can only be accessed by authorized users. Certificate templates are provided for different protocols, usage types and CA backends. Specific validation, whitelisting and RegEx mechanisms or even name composition rules can be configured. E-mail notifications are provided for certain events.
certPort supports the following protocols for certificate requests:
ACME
The Automatic Certificate Management Environment (ACME) protocol according to RFC 8555 is used for the enrollment of TLS certificates from a CA to a server. It can also be used to autoenroll certificates to client computers and mobile devices. certPort supports standard ACME validation types like HTTP, DNS, TLS-ALPN and also newer types like Device-Attestation and DNS-persist. Extended security mechanisms for internal or external servers like ACME acceptance or EAB tokens are provided. certPort supports many popular ACME clients.
EST
Enrollment over Secure Transport (EST) according to RFC 8295 is a modern, secure successor to SCEP. It serves to automatically assign and renew X.509 certificates to machines & IoT devices. certPort supports EST with standard and extended features like server-side key-gen or CoAPS. Initial enrollment can be performed based on pre-defined passwords or pre-installed manufacturer certificates (vendor mode).
SCEP
The Simple Certificate Enrollment Protocol (SCEP) according to RFC 8894 is widely used for network devices, computers and mobile devices. certPort supports three variants for the provisioning of the SCEP challenge: Static for legacy environments, Dynamic for NDES compatibility and Intune for cloud-managed devices.
Deployment Options
certPort is a web application that can be deployed in the following ways:
- As an Azure Web App using Azure App Service
- On an AD-joined Windows Server
- On a standalone Windows Server
Azure Deployment
The deployment of certPort as an Azure Web App service is recommended, if you want to
- enroll certificates to your clients and devices managed by Intune
- enroll certificates to your Entra ID users
- request certificates for your Azure Kubernetes containers
- issue certificates from the Secardeo certVault cloud CA
- issue certificates from a Public CA
Access and management of certPort is done by members of an EntraID admin group.
Active Directory Deployment
The deployment of certPort as an IIS Web App on an AD-joined server VM is recommended, if you want to
- enroll certificates to your clients and devices managed by on-premises MDMs
- request certificates for your internal or public web servers
- replace your outdated MS NDES component
- use Active Directory Certificate Templates
- issue certificates from your Microsoft CA (ADCS) or an Open Source CA
- issue certificates from a Public CA
Access and management of certPort is done by members of an Active Directory admin group.

