What is the difference between On-Premises and Managed PKI & CLM?
With an On-Premises PKI & CLM, MTG Corporate PKI & CLM is operated within the company’s own infrastructure and fully integrated into the existing IT and security architecture. This allows companies to determine the level of control they want to maintain over systems, processes, and key management. With DARZ Managed PKI & CLM powered by […]
What is the difference between private and public certificates?
The key difference lies in the trust model. With private certificates, the company or operator of the private PKI determines which systems trust its CA. They are therefore particularly suitable for controlled enterprise and infrastructure environments. Publicly trusted certificates, by contrast, are issued by Public CAs whose trust anchors are already included in widely used […]
What is a public certificate?
A public certificate is a certificate issued by a publicly trusted Certification Authority (Public CA). The CA’s root certificates are included as trusted roots in widely used operating systems, browsers, and applications. Public certificates are particularly necessary when systems or services need to be trusted by external endpoints that are not managed by the company, […]
What is a private certificate?
A private certificate is a digital certificate issued by a private or enterprise-controlled trust infrastructure. It is trusted only by systems on which the corresponding private CA has been configured as a trust anchor. Private certificates are suitable, for example, for internal servers and applications, users and devices, VPN and network access, machine-to-machine communication, or […]
What does On-Premises or Managed operation mean for a PKI?
With an On-Premises PKI, the PKI is operated within the company’s own infrastructure and integrated into the existing IT and security architecture. Operation and management can be handled by the company’s own team or by MTG. Alternatively, MTG Corporate PKI & CLM can be obtained as a Managed Service through our partner DARZ. The service […]
When does it make sense to operate your own PKI, and when can a Managed Service meet regulatory requirements?
An in-house On-Premises PKI is particularly useful when companies require a high degree of control over infrastructure, processes, key material, and integrations, or when they intentionally want to retain responsibility for PKI operations themselves. A Managed Service can be a suitable alternative if technical and regulatory requirements can also be met through an externally operated […]
What options are available for obtaining or operating certificates and PKI services?
Companies can use different models depending on their use case. Publicly trusted certificates are obtained from Public CAs or trust centers and are used, for example, for publicly accessible websites, servers, or services. For private certificates, companies can operate their own PKI or use a Managed PKI service. With an On-Premises solution, the PKI remains […]
Who is a PKI relevant for?
A PKI is relevant for companies and organizations that want to reliably secure digital identities and automate certificate-based processes. Typical use cases include authenticating users, devices, servers, and applications, securing network access, encrypted communication, digital signatures, and IoT and machine-to-machine communication. A PKI is particularly relevant in larger or heterogeneous IT environments, as well as […]
What is a Registration Authority (RA)?
A Registration Authority (RA) performs tasks that take place before the actual certificate issuance. For example, it verifies identities and request data, implements approval processes, and forwards approved certificate requests to the responsible Certification Authority. This makes it possible to organizationally separate verification and certificate issuance.
When is a Root CA operated offline?
An Offline Root CA is used when particularly high requirements apply to protecting the central trust anchor of a PKI. Its private key remains disconnected from the network during normal operations. The Root CA is activated only for a limited number of controlled operations, such as issuing or renewing Sub-CA certificates or making structural changes […]