NFQES is now becoming 4SIGNER

Enterprise
CA

A system for complete digital certificate lifecycle management — from request intake, through issuance and administration, to expiry. Designed for both qualified and internal certificate authorities.

Enterprise CA

A certificate authority under your control

Enterprise CA enables operation in line with legislative and international certification schemes, including qualified services under eIDAS.
Benefits

Complete PKI management

Your entire PKI infrastructure managed from a single system — from the request to certificate expiry.

Security and auditability

Electronically signed audit records, advanced logging and reports for supervisory and regulatory bodies.

Regulated and internal schemes

Operate qualified certificate authorities under eIDAS as well as internal CAs with a self-signed certificate.

Scalability and flexibility

On-premise deployment, parallel operation of multiple CAs, and scaling for large organizations and public institutions.

Functional architecture

Three layers
of the certification service

The system covers the full certificate lifecycle, trust hierarchy management, and publication and validation services.

Certificate lifecycle

Certificate management from request intake and validation, through issuance, to expiry.

PKI hierarchy

Management of certification structures and the hierarchical trust chain, including root certificates.

Publication and validation services

CRL generation and OCSP services for online certificate status checking.

Who it’s for

Pre každú
certifikačnú schému

Riešenie je navrhnuté pre kvalifikované aj interné certifikačné autority, veľké organizácie a štátne inštitúcie.

Kvalifikované CA

Poskytovatelia dôveryhodných služieb prevádzkujúci kvalifikovanú certifikačnú autoritu podľa eIDAS.

Interné CA

Organizácie budujúce internú certifikačnú autoritu so self-signed koreňovým certifikátom.

Štátne inštitúcie

Veľké organizácie a inštitúcie vyžadujúce škálovateľnú a auditovateľnú PKI.

TLS a systémové certifikáty

Firmy vydávajúce TLS certifikáty a certifikáty pre vlastné systémy a služby.

Technical specifications

Full support for standards
and certificate policies

Cryptographic standards

Support for international standards for certificates and status validation.

INCLUDES:

Cryptographic algorithms

Supported signing and hashing algorithms.

INCLUDES:

Operational requirements

Supported operating systems, key stores and databases.

INCLUDES:

All certificate types

Certificates for natural persons, legal entities, mandate certificates and TLS certificates per customer policies.

QSCD device support

Compatible with devices using the PKCS #11 interface.

Real-time OCSP

Certificate status validation per the RFC 6960 standard.

Robust integration

The solution can be operated with any certificate authority.

Multiple instances

High availability and reliability through a scalable architecture.

eIDAS compliance

The application meets the requirements of Regulation (EU) No 910/2014 and Slovak legislation.

References – selected projects

Trusted by companies
and institutions

The 4SIGNER solution can be implemented and adapted for a wide range of processes for businesses across many fields.

Tatraleasing

Reduced workload, lower hardware requirements, savings in time and cost, and a high level of legal certainty.

Medante

Digital signatures for medical documentation and contracts, implemented within the existing MEDANTE system.

BVS

Digitalized communication, online forms and contracts, electronic signing through the infrastructure or the API.

All certificate types and profiles are supported according to the customer’s chosen certificate policies — certificates for natural persons (electronic signature), legal entities (electronic seal), mandate certificates, TLS certificates and others.

Yes. With on-premise deployment the whole system can be installed at the customer site, a root certificate signed by a superior authority can be integrated, a proprietary trust service can be created, or an internal CA with a self-signed certificate can be operated.

The system generates and publishes CRLs (Certificate Revocation Lists) and provides OCSP services for real-time online certificate status validation per RFC 6960.

Access is role-based: CA operator, CA administrator, CA auditor, security expert and further roles defined by the organization.

Yes. The system supports parallel operation of multiple CAs, including a hierarchy of superior and subordinate authorities.

The solution allows operation in line with legislative and international certification schemes, including qualified services under eIDAS and Slovak legislation.

Still have questions?

Just ask — we’ll gladly help with both the choice and the deployment.

Deploy Enterprise CA
within your infrastructure

We’ll prepare a quote and a deployment plan tailored to your environment — no obligations.