Enterprise Resource Security Mastering Cryptographic Key Lifecycles
ERS

Future-proof PKI.
Simply ready to go.

The MTG ERS® Appliance is preconfigured, is set up step by step, and is ready for productive operation on your own infrastructure.

Appliance-Übersicht der ERS Appliance: Cluster erreichbar, drei Nodes bereit

Five reasons why it simply fits.

From the first start to ongoing operation – the appliance simplifies the setup and administration of your PKI.

Ready in minutes.

Not in weeks.

The appliance largely sets itself up. A wizard guides you step by step through all the important decisions until your first certificate is issued. No consulting project, no long implementation period, and none of the costs of a traditional implementation project.

Startseite der ERS Appliance mit Installations-Assistent, der die Installation Schritt für Schritt durchführt

PKI without PKI specialists.

Easy to operate for any IT team.

Secure default settings and a clear, modern interface take the complexity off your team's hands. The solution can be integrated into your existing Microsoft environment. Common protocols such as ACME, EST, SCEP, and CMP let you automate certificate processes. This way, your IT runs the PKI day to day without any cryptography expertise.

Komponentenübersicht der ERS Appliance: neun Dienste wie ACME, EST, SCEP und CMP sind bereit

High availability, already built in.

From mid-sized companies to large corporations.

If a node fails, your certificate services continue to run without interruption. Clustering, backup and restore, monitoring, and central logging are already integrated. Start small and grow to several million certificates – without migration and without changing systems.

Topologie mit drei Knoten für Hochverfügbarkeit, verschlüsselte Backups und Wiederherstellung aus Backup

Runs wherever your IT runs.

Your infrastructure, your rules.

Whether in your own data center on VMware, Proxmox, KVM, Hyper-V, or Nutanix, in isolated networks without internet access, or with cloud providers such as AWS, Azure, Google Cloud, or STACKIT: the same software runs everywhere with the same license. Your keys and data stay where you decide, and under your control.

Auswahl der Virtualisierungsplattform Proxmox oder VMware mit Ressourcenanforderungen an die Ziel-VMs

Built for the coming decades.

Modern, transparent, and PQC-ready.
Updates enable the introduction of new cryptographic algorithms and support the transition to post-quantum cryptography. An included Software Bill of Materials (SBOM) shows at any time which components are in your appliance. The appliance, developed by MTG, is based on Talos Linux and Kubernetes. MTG brings 30 years of experience in cryptography and is ISO 27001 certified.
RSA- und Post-Quanten-CA-Hierarchie nebeneinander nach einem Update, mit Download der SBOM
How it works

Four steps to your first certificate.

No consulting project, no manual marathon: a wizard in your browser guides you from an empty VM to a ready-to-use PKI. You make the decisions – the appliance does the rest.
01

Deploy

Start a VM or container – fully preconfigured.
02

Follow the wizard

Choose your platform and topology. The wizard guides you through the installation.
03

Set up your PKI

Create a CA hierarchy with recommended defaults – without specialist knowledge.
04

Get started

Issue your first certificate. From now on, your PKI is running.

ERS Appliance vs. Managed PKI

Two paths to your PKI

Operate it yourself or have it operated: both paths lead to a professional PKI from MTG. What matters is which operational tasks you want to take on yourself and how much control you need.
Need help with your decision?We'll be happy to advise you.

Criterion

SELF-OPERATED

ERS Appliance

Your PKI in your infrastructure

OPERATED FOR YOU

Managed PKI & CLM

As a service from German data centers

Operation

Your IT team operates the PKI itself. Wizards and secure default settings support setup and administration.

Our partner DARZ takes over the operation of the PKI for you.

Location of keys and data

Wherever you want: in your own data center or in the cloud of your choice.

In German data centers in Darmstadt and Frankfurt am Main.

Networks without internet access

Fully supported: installation and operation also in isolated networks. You simply upload release packages.

Internet connection required; VPN access optionally available in the BUSINESS and ENTERPRISE plans.

Infrastructure

VMs on your existing virtualization environment.

In the certified data center of our partner DARZ.

Start

Deploy Management and set up the appliance with the help of the wizard.

Register and start with the FREE plan.

High availability

Integrated; configurable for high-availability operation with multiple nodes.

Part of the service.

HSM

Connection of your own HSM. We will be happy to advise you on the selection.

In the BUSINESS and ENTERPRISE plans: CA keys in PQC-capable, certified HSMs.

Control and customization

Full control over configuration, updates, and access.

Range of functions flexibly selectable via plans.

Cost model

Individual offer on request.

The ERS Appliance fits, if …

The Managed PKI fits, if …

Downloads & Links

Talk to us

Our PKI team will show you in a live demo how to set up the MTG ERS® Appliance and use it in your environment.
SD, PKI-Experte bei MTG
WordPress Cookie Plugin by Real Cookie Banner