Enterprise Resource Security Mastering Cryptographic Key Lifecycles

Use Cases – What applications is MTG CARA suitable for?

MTG CARA serves as the technical foundation for a wide range of PKI scenarios and can be configured according to the requirements of the respective company or industry. Based on MTG CARA, we implement Corporate PKIs, IoT PKIs, Trust Center PKIs, Smart Metering PKIs, TSE PKIs, and eID PKIs, among others. The platform is also […]

LDAP/Active Directory – Can MTG CARA be integrated with directory services?

Yes, MTG CARA can be integrated with LDAP directory services and Microsoft Active Directory. Certificates and Certificate Revocation Lists (CRLs), for example, can be exported to LDAP servers or Active Directory. This allows existing centralized directory structures to continue to be used for distributing and providing PKI information.

Role and Rights Management – Does MTG CARA support different permission levels?

Yes, MTG CARA provides a differentiated role and rights model. This allows responsibilities to be separated and organizational structures to be represented within the PKI. The separation of roles and permissions supports the secure operation of PKI infrastructures with elevated security and compliance requirements, for example in accordance with BSI TR-03145.

Compliance – Which security and compliance requirements does MTG CARA support?

MTG CARA is designed for environments with high security and compliance requirements. The platform can be operated in accordance with the requirements of BSI TR-03145 and combined with appropriately certified Hardware Security Modules. In addition, MTG’s processes, including software development, are ISO 27001 certified. Which regulatory and compliance requirements are met in a specific deployment […]

Crypto Agility – Can MTG CARA flexibly support cryptographic algorithms?

Yes, MTG CARA is designed with crypto agility in mind. Cryptographic algorithms can therefore be used according to the applicable security requirements and replaced when necessary. MTG CARA also already supports Post-Quantum Cryptography (PQC). This helps companies prepare their PKI for new cryptographic requirements and future migration scenarios.

HSM Support – Does MTG CARA support Hardware Security Modules?

Yes, MTG CARA supports the integration of Hardware Security Modules (HSMs) to securely generate, store, and use cryptographic keys. Integration can be implemented through PKCS#11 or vendor-specific interfaces. Supported solutions include products from Utimaco, Thales, Entrust, and Securosys, as well as different HSM form factors such as LAN HSMs, smart cards, and USB HSMs.

Integration – How can MTG CARA be integrated into existing applications and systems?

MTG CARA provides various options for integration into existing IT and application environments. Applications and target systems can be connected through REST interfaces, LDAP, and CMP, among other methods. The REST API can be used, for example, to integrate Registration Authorities, Certificate Lifecycle Management solutions, or customer-specific front ends. This allows PKI functionality to be […]

Certificate Formats – Which certificate types does MTG CARA support?

MTG CARA supports different certificate formats and application areas. These include X.509 certificates, Card Verifiable Certificates (CVCs), Attribute Certificates (ACs), and Post-Quantum Cryptography certificates. Certificate templates can also be configured for use cases such as CAs, email, TLS, IoT, network devices, and mobile devices.

Multi-Tenancy – Does MTG CARA support multi-tenant environments?

Yes, MTG CARA supports multi-tenancy. This allows large numbers of certificates to be structured and managed separately according to a domain or tenant model. For example, different organizations, business units, or customers can be represented within a shared PKI platform.

WordPress Cookie Plugin by Real Cookie Banner