Why is Certificate Lifecycle Management becoming increasingly important for companies?
The number of digital certificates and machine identities continues to grow due to cloud infrastructures, IoT, mobile devices, microservices, Zero Trust architectures, and increasing automation. At the same time, requirements for security, transparency, and traceability are increasing. Centralized Certificate Lifecycle Management helps companies manage this growing certificate landscape in a controlled manner and automate certificate […]
Is a CLM also useful for smaller companies?
Yes, a CLM can also be useful for smaller companies, particularly when the number of certificates is growing or certificates are used for business-critical systems. Even a manageable number of manually administered certificates can increase operational effort and the risk of outages. The key factors are therefore less about company size and more about the […]
How does CLM differ from a PKI?
A PKI provides the technical trust infrastructure. The Certification Authority within the PKI issues certificates and cryptographically signs them. A CLM complements the PKI with centralized management and automation of certificate processes throughout the entire lifecycle. With MTG Corporate PKI & CLM, we combine MTG CARA as the Certification Authority with MTG CLM for lifecycle […]
What role do HSMs play in the context of MTG CLM?
Hardware Security Modules (HSMs) protect particularly sensitive cryptographic key material and perform cryptographic operations in a specially secured environment. MTG CLM supports the integration of HSMs and Crypto Modules through standardized interfaces such as PKCS#11. Both On-Premises HSMs and Cloud HSM offerings can be integrated. In combination with MTG CARA, the private keys of Certification […]
What is the MTG Autoenrollment Connector?
The MTG Autoenrollment Connector makes it possible to replace Microsoft AD CS as the issuing PKI with MTG CARA while continuing to use established Windows autoenrollment mechanisms. Existing processes such as autoenrollment, Group Policies, and Microsoft certificate templates can be integrated into the new PKI structure. The migration requires corresponding configuration steps, for example for […]
What is the Microsoft CA Connector in MTG CLM?
The Microsoft CA Connector can be used to connect an existing Microsoft PKI based on AD CS to MTG CLM. The Microsoft CA remains the issuing Certification Authority, while certificates can be requested and managed through MTG CLM. In the technical documentation, this integration is referred to as the Microsoft CA Certificate Provider. This allows […]
What integrations does MTG CLM provide?
MTG CLM provides various integrations for existing enterprise and PKI environments. These include Microsoft PKI (AD CS), various Public CAs, Microsoft Active Directory, Microsoft Entra ID, Keycloak, and Microsoft Intune. Standardized PKI protocols as well as REST API and CLI interfaces are also available for integration with applications, automation platforms, and custom processes.
Can MTG CLM manage public and private certificates?
Yes, MTG CLM can centrally manage both private and publicly trusted certificates. Private certificates can, for example, be provided through MTG CARA or a connected Microsoft CA. Direct Certificate Provider integrations are available for public certificates. These currently include, among others, GlobalSign, Deutsche Telekom Security via PCSP, and selected Sectigo certificates via PSW.
Can MTG CLM manage multiple PKIs and Certification Authorities at the same time?
Yes, MTG CLM is designed to centrally integrate different Certification Authorities and Certificate Providers. This makes it possible to manage certificates from different private and public PKI environments through a single centralized platform. Supported providers include MTG CARA, Microsoft CA, and various Public CA providers. The available functions may differ depending on the connected Certificate […]
What role does CLM play in the context of regulation, for example KRITIS or DORA?
MTG CLM can help companies address regulatory and internal security requirements by transparently recording certificate inventories and ensuring that processes are standardized, controlled, and traceable. However, a CLM alone does not establish regulatory compliance. Compliance always depends on the interaction of technical measures, processes, responsibilities, and the selected operating model.