Product ยท Signing & CA integrations

Sign against the CA you already run

Certheim doesn't replace your certificate authority; it drives it. Connect one backend or several, govern them with per-template policy, and sign from the dashboard without keys ever touching a workstation.

In-UI, policy-gated signing

Submit a CSR and sign it from the dashboard: approval-gated, template-governed, and fully audited.

Per-template policy

Each certificate template names its CA backend, its approval rule, and its renewal window. Trusted templates auto-sign; sensitive ones demand a human approver.

Configurable subject & profiles

Define your organization's subject DN, OUs, and domains once, then switch identity per request with named subject profiles. Requests inherit the right shape automatically.

Revocation built in

Revoke from the dashboard with CRL and OCSP support, so a compromised certificate is dead everywhere, not just deleted from a spreadsheet.

CA backends

Mix and match per template: one workflow over every authority you operate.

๐Ÿ”

OpenBao / Vault PKI Community

First-class PKI-engine integration with AppRole auth. The free, self-hosted starting point signs real certificates on day one.

๐ŸชŸ

Microsoft AD CS Commercial In validation

Enroll against enterprise Active Directory Certificate Services templates, the CA most Windows estates already trust.

๐Ÿข

EJBCA & Venafi Commercial Design-partner

Drive an existing EJBCA deployment or a Venafi-managed issuance flow without changing how your PKI team governs them.

โ˜๏ธ

AWS Private CA Commercial Design-partner

Issue from AWS Private CA with native SigV4 signing, so hybrid estates keep one request workflow across cloud and on-prem.

๐Ÿ”

ACME client Commercial

Enroll against any RFC 8555 ACME directory (internal step-ca or public CAs) with HTTP-01 and cloud DNS-01 solvers (Cloudflare live today; Route 53 and Azure DNS in validation).

๐Ÿ—„๏ธ

CyberArk Commercial Design-partner

Sign via CyberArk Certificate Manager and store issued material back into CyberArk-governed safes.

A complete built-in CA for when you don't have one

No external authority? The local CA Commercial In validation makes Certheim self-contained: generate or import a CA whose key lives sealed in the encrypted keystore, and issue directly.

Full issuance stack

Sign CSRs locally with TLS and S/MIME profiles, host the CRL, and answer OCSP, with AIA/CDP URLs stamped into every certificate it issues.

Post-quantum ready

Stand up ML-DSA-65/87 certificate authorities alongside classical ones (OpenSSL 3.5+), so you can pilot post-quantum chains before your mandate arrives.

Standards enrollment

The local CA fronts the same EST, SCEP, and CMP enrollment services as any external backend; devices can't tell the difference. More on enrollment โ†’

Where the keys live

Encrypted keystore Commercial

An envelope-encrypted, sealed store for signing keys: selectable AES-256 cipher tiers, Shamir or passphrase unseal, and offline escrow backup. No external vault required.

External vault

Prefer your own secret store? Keep keys in OpenBao/Vault and let Certheim fetch per-operation; keys at rest never live in the app's database.

HSM / PKCS#11 Add-on Design-partner

Anchor CA keys in a hardware security module over PKCS#11 for deployments where keys must be hardware-backed, with FIPS-aligned key ceremonies in the Government edition.

Next up

See it for yourself

Generate a key and CSR in your browser, walk the guided setup, or stand up Community for free. No sales call required.

Questions first? Talk to us. Design partners and air-gapped evaluations are welcome.