Enterprise
CA
A system for complete digital certificate lifecycle management — from request intake, through issuance and administration, to expiry. Designed for both qualified and internal certificate authorities.
A certificate authority under your control
Complete PKI management
Security and auditability
Electronically signed audit records, advanced logging and reports for supervisory and regulatory bodies.
Regulated and internal schemes
Operate qualified certificate authorities under eIDAS as well as internal CAs with a self-signed certificate.
Scalability and flexibility
Three layers
of the certification service
The system covers the full certificate lifecycle, trust hierarchy management, and publication and validation services.
Certificate lifecycle
Certificate management from request intake and validation, through issuance, to expiry.
- Certificate request intake and validation
- Certificate issuance and renewal
- Suspension, reinstatement and revocation
- Self-renewal — remote upload of the certificate to the card
PKI hierarchy
- Root certificate management
- Superior and subordinate certificate authorities
- Certificate profiles and templates
- Self-signed roots or roots signed by a superior authority
Publication and validation services
CRL generation and OCSP services for online certificate status checking.
- CRL generation and publication
- OCSP server per RFC 6960
- Real-time certificate status validation
Pre každú
certifikačnú schému
Riešenie je navrhnuté pre kvalifikované aj interné certifikačné autority, veľké organizácie a štátne inštitúcie.
Kvalifikované CA
Poskytovatelia dôveryhodných služieb prevádzkujúci kvalifikovanú certifikačnú autoritu podľa eIDAS.
Interné CA
Organizácie budujúce internú certifikačnú autoritu so self-signed koreňovým certifikátom.
Štátne inštitúcie
Veľké organizácie a inštitúcie vyžadujúce škálovateľnú a auditovateľnú PKI.
TLS a systémové certifikáty
Firmy vydávajúce TLS certifikáty a certifikáty pre vlastné systémy a služby.
What your company gains
from deploying Enterprise CA
From unified PKI management to full auditability and legal compliance.
One system for the whole PKI
Complete PKI management from a single place, with no fragmented tooling.
Auditability and reporting
Signed audit records and reports ready for supervisory bodies.
Multiple CAs in operation
Parallel operation of several certificate authorities within one installation.
Legal compliance
Meets the requirements of Regulation (EU) No 910/2014 (eIDAS) and Slovak legislation.
Full support for standards
and certificate policies
Cryptographic standards
Support for international standards for certificates and status validation.
INCLUDES:
- RFC 5280 — X.509 PKI, certificates and CRL
- RFC 6960 — OCSP
- PKCS #11 — QSCD device support
Cryptographic algorithms
Supported signing and hashing algorithms.
INCLUDES:
- RSA, EC
- MD2, MD4, MD5
- RIPEMD 128/160/256/320
- SHA-1, SHA-224, SHA-256, SHA-384, SHA-512
Operational requirements
Supported operating systems, key stores and databases.
INCLUDES:
- RHEL, Oracle Linux, Ubuntu Linux, Windows
- Key stores: HSM, PEM, JKS
- MySQL, MariaDB, PostgreSQL, Oracle or embedded DB
All certificate types
Certificates for natural persons, legal entities, mandate certificates and TLS certificates per customer policies.
QSCD device support
Compatible with devices using the PKCS #11 interface.
Real-time OCSP
Certificate status validation per the RFC 6960 standard.
Robust integration
The solution can be operated with any certificate authority.
Multiple instances
High availability and reliability through a scalable architecture.
eIDAS compliance
The application meets the requirements of Regulation (EU) No 910/2014 and Slovak legislation.
Trusted by companies
and institutions
The 4SIGNER solution can be implemented and adapted for a wide range of processes for businesses across many fields.
Tatraleasing
Reduced workload, lower hardware requirements, savings in time and cost, and a high level of legal certainty.
Medante
Digital signatures for medical documentation and contracts, implemented within the existing MEDANTE system.
BVS
Digitalized communication, online forms and contracts, electronic signing through the infrastructure or the API.
Which certificate types are supported?
All certificate types and profiles are supported according to the customer’s chosen certificate policies — certificates for natural persons (electronic signature), legal entities (electronic seal), mandate certificates, TLS certificates and others.
Can the system be deployed as an internal certificate authority?
Yes. With on-premise deployment the whole system can be installed at the customer site, a root certificate signed by a superior authority can be integrated, a proprietary trust service can be created, or an internal CA with a self-signed certificate can be operated.
How does the system handle certificate status validation?
The system generates and publishes CRLs (Certificate Revocation Lists) and provides OCSP services for real-time online certificate status validation per RFC 6960.
Which roles does the system support?
Access is role-based: CA operator, CA administrator, CA auditor, security expert and further roles defined by the organization.
Can several certificate authorities run at the same time?
Yes. The system supports parallel operation of multiple CAs, including a hierarchy of superior and subordinate authorities.
Does the solution meet legislative requirements?
The solution allows operation in line with legislative and international certification schemes, including qualified services under eIDAS and Slovak legislation.
Deploy Enterprise CA
within your infrastructure
We’ll prepare a quote and a deployment plan tailored to your environment — no obligations.
More modules
from the Enterprise ecosystem
Enterprise PKI API
PKI · Integration
Enterprise RemoteHSM
Remote access to a dedicated HSM card through a secured API interface.
Enterprise Web Signer
A signing component for user-driven document signing in a web environment.
Signing · On-premise