Roadmap & validation status

We would rather under-promise. Certheim covers a broad integration surface, and the items on this page are built and tested in isolation but not yet validated end-to-end against the live third-party systems they target. We publish them openly so you always know what is production-proven today versus what we will prove together.

How to read this

Available today

Everything not on this page. Certificate issuance and approval, ACME (client and server), OpenBao signing, renewal automation, delivery to SSH hosts / Kubernetes / OpenBao / webhooks, the certificate inventory, RBAC, SSO over OIDC and SAML, and notifications are all validated end-to-end.

In validation

Implemented and unit-tested; we are proving them against the real target system now. These move to "available" as each end-to-end validation completes.

Design-partner validation

Implemented, but they need a live third-party system we do not run in-house. We validate these in your environment during onboarding and promote them to fully supported once proven there.

In validation

Built and unit-tested; live end-to-end validation is in progress.

Microsoft AD CS connector

Signing certificates through an Active Directory Certificate Services CA. Status: in validation.

Built-in Local CA

The self-contained CA for teams without an external PKI, including CRL publication. Status: in validation.

CT-log monitoring

Watching public Certificate Transparency logs for certificates issued for your domains. Status: in validation.

Enrollment servers — CMP, EST, SCEP

Standards-based enrollment endpoints for devices and clients. Status: in validation against live clients.

Enterprise CA connectors

Design-partner validation — proven in your environment during onboarding.

Venafi

Signing through Venafi TLS Protect / TPP. Status: design-partner validation.

EJBCA

Signing through an EJBCA instance. Status: design-partner validation.

AWS Private CA

Signing through AWS Private Certificate Authority. Status: design-partner validation.

CyberArk

Signing via CyberArk Certificate Manager and delivering issued material into CyberArk-governed safes. Status: design-partner validation.

Cloud delivery & DNS

Design-partner validation — needs your cloud account to prove end-to-end.

Cloud secret-store delivery

Delivering certificates into AWS Secrets Manager, Azure Key Vault, and GCP Secret Manager. Status: design-partner validation.

Cloud DNS-01 solvers

ACME DNS-01 challenges via AWS Route 53 and Azure DNS. Status: design-partner validation.

Hardware-dependent

Requires physical or vendor hardware we validate on a per-engagement basis.

HSM / PKCS#11

Protecting CA keys in a hardware security module. Status: validated per engagement.

Appliance delivery

Pushing certificates to Citrix NetScaler, F5 BIG-IP, and A10 appliances. Status: validated per engagement.

Want one of these proven for you?

We run design-partner engagements: we stand the integration up against your system, validate it end-to-end, and promote it to fully supported — at no feature cost to you. If a capability you need is on this page, that is the fastest path to production.