Autoenrollment – Can MTG Corporate PKI be integrated with Microsoft Active Directory?
Yes, the MTG Autoenrollment Connector can integrate MTG Corporate PKI into an existing Microsoft Active Directory environment. This allows Microsoft AD CS to be replaced as the issuing PKI by MTG CARA while established Windows autoenrollment mechanisms continue to be used. The integration requires configuration of items such as certificate templates, Enrollment Policies, Group Policies, […]
Automation – Which certificate processes can be automated with MTG Corporate PKI & CLM?
MTG Corporate PKI & CLM can automate numerous certificate processes—from request and issuance through deployment and renewal—provided that the certificates originate from connected CAs. This currently includes MTG, Microsoft, GlobalSign, and Deutsche Telekom CAs. A particular advantage for users of Microsoft CAs is that certificate processes outside traditional Microsoft environments can also be automated. Examples […]
Documentation – Is online documentation available for the solution?
Yes, comprehensive online documentation is available to all customers. It is publicly accessible and provides the relevant information required to use the solution.
Audit Log – Can security-relevant activities be logged?
Yes, MTG Corporate PKI & CLM logs relevant activities and changes so that certificate and administrative processes can be traced. The Audit Log supports internal controls, audits, and the analysis of security-relevant events. The events and level of detail that are logged depend on the respective MTG ERS® component and its configuration.
Sub CA – Does my company have its own Sub CA in MTG Corporate PKI?
Yes, MTG Corporate PKI can be configured for your company with one or more Root CAs as well as one or more dedicated Sub CAs. This allows the PKI structure to be designed according to the respective business, organizational, or technical requirements.
Offline Root CA – When does an Offline Root CA make sense?
An Offline Root CA is a special deployment model that involves additional manual operational effort. It is kept in a highly protected environment and activated only in exceptional cases, for example when additional Sub CAs need to be created or signed. Such operations are typically required only infrequently. The key advantage of an Offline Root […]
Multiple Root CAs – Can multiple Root CAs be configured?
Yes, multiple Root CAs can be configured with MTG Corporate PKI where required. This can be useful when different trust domains, organizational requirements, or cryptographic methods need to be separated. For example, separate PKI hierarchies can be established for different security domains or for the phased introduction of new cryptographic methods.
Root CA – Can a dedicated Root CA be set up?
Yes, a dedicated Root CA can be established as part of MTG Corporate PKI. The Root Certification Authority forms the highest trust authority within a PKI and is configured accordingly during deployment. Its role is to use its private key to sign one or more subordinate Certification Authorities (Sub CAs). This establishes trust in the […]
Certificate Revocation – What are OCSP and CRLs used for?
OCSP and Certificate Revocation Lists (CRLs) make it possible to determine whether a certificate has been revoked before the end of its regular validity period. MTG Corporate PKI provides an OCSP Responder through the MTG Revocation Info Server. Full and delta CRLs can also be provided over HTTP or published to LDAP directories. This allows […]
Certificate Discovery – How can hidden or unknown certificates be systematically identified within the company?
MTG Certificate Discovery can automatically identify existing and previously unknown certificates and import them into MTG CLM. Available mechanisms include network scans for TLS certificates, searches in LDAP or Active Directory, and Certificate Transparency logs. The discovered certificates can be added to the centralized certificate inventory and evaluated based on validity period, status, and the […]