Product ยท Signing & CA integrations
Certheim doesn't replace your certificate authority; it drives it. Connect one backend or several, govern them with per-template policy, and sign from the dashboard without keys ever touching a workstation.
Submit a CSR and sign it from the dashboard: approval-gated, template-governed, and fully audited.
Each certificate template names its CA backend, its approval rule, and its renewal window. Trusted templates auto-sign; sensitive ones demand a human approver.
Define your organization's subject DN, OUs, and domains once, then switch identity per request with named subject profiles. Requests inherit the right shape automatically.
Revoke from the dashboard with CRL and OCSP support, so a compromised certificate is dead everywhere, not just deleted from a spreadsheet.
Mix and match per template: one workflow over every authority you operate.
First-class PKI-engine integration with AppRole auth. The free, self-hosted starting point signs real certificates on day one.
Enroll against enterprise Active Directory Certificate Services templates, the CA most Windows estates already trust.
Drive an existing EJBCA deployment or a Venafi-managed issuance flow without changing how your PKI team governs them.
Issue from AWS Private CA with native SigV4 signing, so hybrid estates keep one request workflow across cloud and on-prem.
Enroll against any RFC 8555 ACME directory (internal step-ca or public CAs) with HTTP-01 and cloud DNS-01 solvers (Cloudflare live today; Route 53 and Azure DNS in validation).
Sign via CyberArk Certificate Manager and store issued material back into CyberArk-governed safes.
No external authority? The local CA Commercial In validation makes Certheim self-contained: generate or import a CA whose key lives sealed in the encrypted keystore, and issue directly.
Sign CSRs locally with TLS and S/MIME profiles, host the CRL, and answer OCSP, with AIA/CDP URLs stamped into every certificate it issues.
Stand up ML-DSA-65/87 certificate authorities alongside classical ones (OpenSSL 3.5+), so you can pilot post-quantum chains before your mandate arrives.
The local CA fronts the same EST, SCEP, and CMP enrollment services as any external backend; devices can't tell the difference. More on enrollment โ
An envelope-encrypted, sealed store for signing keys: selectable AES-256 cipher tiers, Shamir or passphrase unseal, and offline escrow backup. No external vault required.
Prefer your own secret store? Keep keys in OpenBao/Vault and let Certheim fetch per-operation; keys at rest never live in the app's database.
Anchor CA keys in a hardware security module over PKCS#11 for deployments where keys must be hardware-backed, with FIPS-aligned key ceremonies in the Government edition.
Generate a key and CSR in your browser, walk the guided setup, or stand up Community for free. No sales call required.
Questions first? Talk to us. Design partners and air-gapped evaluations are welcome.