The KeyTalk Certificate Key Management System (CKMS) is a public key infrastructure (PKI) platform designed for the automated lifecycle management of digital certificates and cryptographic keys. It centrally manages the deployment, renewal, and monitoring of TLS/SSL, S/MIME, and X.509 certificates across network devices, servers, and endpoints. The system can operate as a built-in private Certificate Authority (CA), either as a root or subordinate, or as a Registration Authority (RA) connecting to third-party public CAs, providing a central repository for keys and certificates. Deployment options include a virtual appliance, a private cloud installation, or a multi-tenant SaaS offering.
For certificate distribution, the platform integrates with directory services like Active Directory, Entra ID, and LDAP for attribute-based provisioning. It uses protocols such as ACME, SCEP, CMP, and EST to provision certificates to infrastructure including MDM solutions, load balancers, firewalls, and web servers. Endpoint agents for Windows, Linux, and macOS facilitate automated renewals and hardware fingerprinting. Cryptographic keys can be stored in an internal AES-256 encrypted database, an external Hardware Security Module (HSM), or a local Trusted Platform Module (TPM), with security options including hardware signature binding (HWSIG) and TPM attestation. The system also supports network certificate discovery and high availability deployments.