Machine Autoenrollment



Certificate autoenrollment for servers, clients, IoT devices in the Azure cloud or on-premises via ACME, SCEP and EST.


Release is coming soon!

Servers

Auto-enroll trusted TLS certificates from a public CA or your internal CA to your web servers automatically and centrally managed via ACME.


 

Clients

Provide certificates for authentication or VPN to your Windows, Linux, Apple or Android devices automatically via SCEP or ACME!


IoT and OT devices

Automatically provision your Industry  IoT and OT devices with mTLS authentication certificates via the modern EST protocol.



"Secardeo certPort automatically provides all types of IT machines operated and managed in the cloud or on-premises with authentication certificates ."

Avoid server downtime and lower costs!


  • Automatic certificate renewal via ACME prevents from outages due to expired certificates.
  • Constantly decreasing lifetimes of server TLS certificates need frequent renewals.
  • Each manual certificate renewal will cause internal costs.


Enable Zero Trust network access.


  • Autoenroll and -renew certificates for your clients managed by Intune or other MDM systems.
  • Replace your outdated NDES by modern and extended technology for SCEP.
  • Autoenroll certificates for Linux clients or Apple devices using the modern ACME protocol.
  • Validate and compose certificate requests according to your policy
  • Autorevoke Intune SCEP certificates or ACME certificates on request.


On-premises or in your Azure cloud.


  • Deployment as an Azure Web App in your tenant assures full control over the complete service.
  • Full integration with Intune for automated enrollment, management and revocation of device certificates.
  • Out-of-the-box integration with SECARDEO certCAST for issuing certificates in your cloud tenant.
  • Deployment in your Active Directory provides deep integration with ADCS and AD certificate templates.
  • Several CA-Backends for the integration with other private or public CAs are provided.


How it works

More information is coming soon!

  • Features

    • Autoenrolls/-renews machine authentication certificates via SCEP, ACME or EST from your CA
    • Automatically revokes Intune SCEP certificates or ACME certificates on request
    • Validation of algorithm and key parameters, key usage and EKU based on certificate templates
    • ACME support for HTTP, DNS, TLS-ALPN and Device Attestation challenges
    • SCEP request validation with Intune, static or dynamic password or existing certificate
    • EST request validation with vendor certificate, basic authentication or existing certificate
    • Advanced EST features for server-side key generation and enrollment over CoAPS
    • Provides customizable e-mail notifications
    • Support of multiple public or private backend Cas
    • Enhanced ACME security features for ACME acceptance and External Account Binding
    • Management of ACME accounts and EAB tokens
    • Integration with Application Insights and immutable audit log in Azure 

Resources (coming soon!)