Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Revocent ## Sitemaps [XML Sitemap](https://revocent.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [3 Outstanding Reasons ML-KEM Algorithm Destroys RSA](https://revocent.com/ml-kem-algorithm-vs-rsa-quantum-safe-encryption/): The ML-KEM algorithm represents the biggest fundamental shift in enterprise public key cryptography in over four decades. For years, organizations built their entire Public Key Infrastructure (PKI) around RSA integer factorization mathematics, trusting that classical supercomputers could never process the calculations required to crack a 2048-bit or 4096-bit private key. - [Domain Validation Validity: What 10-Day Limits Mean for You](https://revocent.com/domain-validation-validity-10-day-limit/): Navigating changes to domain validation validity rules has become a top priority for enterprise security leaders preparing for CA/Browser Forum Ballot SC-081v3. While engineers readily track the transition from 398 days down to 200 days, followed by 100 days, and ultimately arriving at a 47-day validity window, focusing solely on the certificate expiration date overlooks a far more aggressive operational hurdle: the drastic compression of cached domain authorization data. - [CertAccord Enterprise 8.3 Now Available](https://revocent.com/certaccord-enterprise-8-3-now-available/): CertAccord Enterprise 8.3 by Revocent, Inc., now generally available, adds support for SUSE Linux Enterprise, introduces a new File Base Name attribute for Certificate Purposes, and delivers security hardening across the product. This release also updates all third-party frameworks to their current major versions, addressing security and bugfixes. This release is recommended for all new and existing customers. - [Is the 90-Day TLS Certificate Already Obsolete? Preparing for 2027](https://revocent.com/90-day-tls-certificate-obsolete-2027/): For years, enterprise IT departments viewed the three-month rotation cycle as the gold standard for modern cryptographic hygiene. Driven primarily by automated open-source certificate authorities, the 90-day TLS certificate forced organizations away from legacy, multi-year deployment models, establishing a faster, more secure standard for public-facing infrastructure. - [Security Team Burnout: How to Avoid Certificate Renewal Stress](https://revocent.com/security-team-burnout-how-to-avoid-certificate-renewal-stress/): Cybersecurity professionals currently face an unprecedented wave of systemic fatigue. Between triaging active threats, patching zero-day vulnerabilities, and maintaining complex compliance frameworks, organizations stretch their engineering resources incredibly thin. Consequently, one of the most common catalysts for modern security team burnout isn't a highly sophisticated external exploit—it is the relentless, high-stakes chore of manually renewing digital certificates. - [47-Day Certificate Lifespan: Navigating the CA/Browser Forum Timeline](https://revocent.com/47-day-certificate-lifespan-sc-081-timeline/): The CA/Browser Forum recently transformed the public trust landscape by passing Ballot SC-081v3. This landmark vote establishes a strict, multi-year SC-081 ballot timeline that systematically reduces the maximum allowed validity period for public TLS certificates. Security teams must fundamentally shift their operations to prepare for a "final" 47-day certificate lifespan. Because this change eliminates the traditional one-year renewal cycle, organizations must pivot away from manual intervention. Consequently, implementing programmatic, policy-driven automation represents the only viable path to prevent widespread production outages as the deadlines approach. - [SAN Certificate Management: Navigating the 47-Day Window](https://revocent.com/san-certificate-management-navigating-the-47-day-window/): Enterprises must fundamentally change their approach to SAN certificate management as the industry moves toward a 47-day maximum validity period. Historically, Subject Alternative Name (SAN) configurations allowed administrators to secure multiple domains under a single umbrella, which simplified licensing. However, as the industry forces the certificate lifecycle into a high-velocity cycle, maintaining multi-domain TLS agility becomes an immense operational burden. Consequently, organizations must pivot toward automation to prevent the inevitable outages caused by manual configuration errors in these complex, multi-domain environments. - [Cryptographic Automation: Securing the PKI Inflection Point](https://revocent.com/cryptographic-automation-pki-inflection-point/): The digital landscape has officially reached an inflection point where traditional certificate management methods no longer suffice. For years, IT departments treated digital certificates as static assets—identities you could manage with a spreadsheet and a calendar reminder. However, the modern enterprise network has evolved into a high-velocity environment of short-lived cloud instances and microservices. Consequently, organizations must pivot toward cryptographic automation to maintain stability. - [Quantum Readiness 2029: Preparing for the Q-Day Shift](https://revocent.com/preparing-for-quantum-readiness-2029/): Google recently sent a wake-up call through the cybersecurity community by accelerating its timeline for "Q-Day." Experts previously viewed the point when quantum computers could shatter modern encryption as a distant problem. However, the new target for quantum readiness 2029 forces enterprises to confront this threat within the next few years. This shift means that the cryptographic foundations we rely on today, such as RSA and ECC, face an expiration date. Consequently, organizations must act now to implement crypto-agility and protect their long-term data against "harvest now, decrypt later" attacks. - [Certificate Lifecycle Management for Enterprise PKI Efficiency](https://revocent.com/certificate-lifecycle-efficiency/): Certificate lifecycle management acts as the foundation of a secure and stable digital environment. In a modern enterprise, certificates establish trust between every server, application, and internal service. However, without a structured process, this trust becomes a liability. - [Certificate Expiration Time Is Dropping to 47 Days](https://revocent.com/certificate-expiration-47-days/): The industry is currently undergoing a massive shift in how public trust works. Driven by Google’s roadmap and the CA/Browser Forum, the maximum allowed certificate expiration time for public TLS certificates is shrinking rapidly. Industry leaders plan to reduce this window in stages until it hits just 47 days by March 2029. - [PKI Security Standards and the New Post-Quantum RFC 9909](https://revocent.com/pki-security-standards-rfc-9909/): PKI security standards continue to evolve as cryptographic risks change. One of the most important updates comes from RFC 9909, an Internet Engineering Task Force specification that defines how post-quantum signature algorithms integrate into existing X.509 certificate structures. - [PKI Management for Continuous Availability](https://revocent.com/pki-management-continuous-availability/): PKI management acts as the silent engine for modern enterprise security. Certificates build the essential "handshake" of trust between internal systems, apps, and services. However, as businesses grow, this web of trust becomes hard to navigate. - [PKI Automation for Enterprise Security](https://revocent.com/pki-automation-enterprise-security/): PKI automation has become essential for enterprise security as threats increase and internal systems rely on more digital certificates than ever before. As organizations scale, manual digital certificate management creates risk, increases operational pressure, and leaves room for costly mistakes. - [PKI Security: The Crucial Role in Building a Zero Trust Model](https://revocent.com/pki-security-the-crucial-role-in-building-a-zero-trust-model/): PKI security provides the foundation for zero trust. Digital certificates serve as cryptographic proof of identity, validating users, devices, and services. They enable encryption for internal communications and ensure that sensitive systems and data are only accessed by authorized entities. Without PKI, zero trust policies cannot be reliably enforced. - [Revocation Management and Expiration Tracking: Why They Matter](https://revocent.com/revocation-management-expiration-tracking/): As enterprises grow, their internal systems rely on hundreds or even thousands of certificates. Maintaining the security and reliability of these credentials requires mastering two essential disciplines: revocation management and expiration tracking. These certificates protect service communication, authenticate devices, and help enforce access controls. When they aren't managed well, small issues turn into major disruptions. - [Certificate Security at Scale with Revocent’s CertAccord Enterprise](https://revocent.com/certificate-security-at-scale-with-revocents-certaccord-enterprise/): Managing certificate security in large enterprises goes far beyond just renewing SSL/TLS certificates before they expire. In organizations with thousands of devices, applications, and users, digital certificates form the backbone of trust and encryption. Without proper management, even one overlooked certificate can cause outages, security breaches, or compliance failures. - [Crypto Agility: Adapting to Changing Encryption Standards](https://revocent.com/crypto-agility-encryption-standards/): Modern encryption doesn’t stand still. What protects your systems today could become a risk tomorrow. That’s why crypto agility—your ability to shift encryption strategies quickly—isn’t optional anymore. It’s essential. - [Certificate Lifecycle Management: The Renewals Dilemma](https://revocent.com/certificate-lifecycle-renewal-management/): The certificate lifecycle includes one deadline you can't ignore—renewals. Missing a renewal can knock systems offline, expose security gaps, or trigger regulatory penalties. Whether you're securing public services, internal apps, or APIs, every TLS/SSL certificate needs timely renewal to maintain digital trust. - [Certificate Renewal: Prevent Downtime from TLS/SSL Expiration](https://revocent.com/certificate-renewal-chaos/): When digital X.509 certificates expire, the results can be severe. Systems go offline, secure communications break down, and your organization could face reputational and financial damage. For IT professionals and security leaders, staying ahead of certificate renewal isn't optional—it’s essential. - [Certificate Monitoring: Protect Your PKI](https://revocent.com/certificate-monitoring-pki-strategy/): Certificate monitoring gives teams real-time insight into every certificate in their environment. Without it, certificates can expire unnoticed, misconfigurations can happen, or attackers can exploit compromised credentials. - [How To Create Trusted X.509 Certificates On MacOS](https://revocent.com/how-to-create-trusted-x-509-certificates-on-macos-x/): Creating trusted enterprise certificates on Apple's MacOS has never been easy, but it can be. - [How to Detect Expiring Certificates](https://revocent.com/how-to-detect-expiring-certificates/): Elephants and Other Hi-Tech Methods - [CertAccord – How To Create Trusted Certificates From Command Line On Linux](https://revocent.com/certaccord-how-to-create-trusted-certificate-from-command-line-linux/): Creating a trusted X.509 certificate on Linux (Red Hat Enterprise Linux (RHEL), Ubuntu Linux, and MacOS) is fast and simple using CertAccord Enterprise.  Most any IT system administrator can create certificates without having to be a PKI expert. - [Best Practices for Securing Private Keys](https://revocent.com/best-practices-for-securing-private-keys/): When you leave home do you lock the front door but leave the key in the lock?  That's the same thing as creating a private key but not protecting it. Access to a private key can let an attacker fraudulently sign application content or impersonate a site's identity.  Common sense would indicate that locking your front door and taking the key with you is a good thing so have you asked yourself if your private keys are secure? - [How to Configure Apache Tomcat With Fully Managed TLS Certificates](https://revocent.com/how-to-configure-apache-tomcat-with-fully-managed-tls-certificates/): Apache Tomcat is a popular open source application server used on Red Hat Enterprise Linux (RHEL), Ubuntu Server, other Linux distributions, MacOS, and Windows Server.  One of the most critical best practices for securing Tomcat is to configure SSL/TLS (HTTPS) using a trusted certificate from your enterprise CA or commercial CA.  Most of the documentation found online on how to configure SSL/TLS for Tomcat provides instructions for creating a self-signed certificate.  Self-signed certificates are not secure and should be avoided. - [How To Create And Manage Certificates in JKS on Windows, Linux, and MacOS](https://revocent.com/how-to-create-and-manage-certificate-in-jks-on-windows-linux-and-macos/): Applications (especially Java applications) that use HTTPS (SSL/TLS) require X.509 certificates to be  provided typically in a Java Key Store (JKS) or PKCS#12 file. This post describes how you can automatically create certificates in JKS from a Microsoft PKI Certificate Authority or GlobalSign Certificate Authorities using the fully automated CertAccord Enterprise solution that not only quickly provisions the initial certificate but also automatically renews and updates the certificate prior to expiration. CertAccord Enterprise supports JKS and other formats on Windows, Linux, and Mac platforms. - [How To Create Certificates in PKCS12 on Windows, Linux, and MacOS](https://revocent.com/how-to-create-certificates-in-pkcs12-on-windows-linux-and-macos/): Applications (especially Java applications) that use HTTPS (SSL/TLS) require X.509 certificates to be provided typically in a PKCS#12 (PKCS12, P12) file. This post describes how you can automatically create certificates in PKCS12 from a Microsoft PKI Certificate Authority or GlobalSign Certificate Authorities using the fully automated CertAccord Enterprise solution that not only quickly provisions the initial certificate but also automatically renews and updates the certificate prior to expiration. CertAccord Enterprise supports PKCS12 and other formats on Windows, Linux, and Mac platforms. - [CertAccord – How To Create Trusted Certificates From Command Line On MacOS](https://revocent.com/certaccord-how-to-create-trusted-certificates-from-command-line-on-macosx/): Creating a trusted X.509 certificate on Apple's MacOS (as well as Linux) is fast and simple using CertAccord Enterprise.  Most any IT system administrator can create certificates without having to be a PKI expert. Often times IT staff are thinking about how to create a certificate signing request mac when in fact they should be thinking about how to create a certificate using an automated solution such as CertAccord Enterprise. - [Certificate Automation for Large Networks: Stay in Control](https://revocent.com/certificate-automation-large-networks/): Managing digital certificates across a growing network is no small task. As organizations scale, manual methods of tracking and renewing certificates create serious risks. A single overlooked expiration can lead to outages, security gaps, or compliance violations. This is where certificate automation becomes essential. By using tools designed for automated tracking, IT teams can maintain control over thousands of certificates without added stress or risk. - [MS-WCCE Automated Solution for Linux](https://revocent.com/ms-wcce-automated-solution-for-linux/): Windows systems have long supported Microsoft Windows Client Certificate Enrollment (MS-WCCE) which provides automatic X.509 certificate deployment and renewal with Microsoft Active Directory Certificate Services (ADCS).  Linux systems have no MS-WCCE support or any other automated integration with ADCS.  This is a key reason we created CertAccord Enterprise. - [Configuring Apache HTTPD TLS Using Microsoft ADCS Certificates](https://revocent.com/configuring-apache-httpd-tls-using-microsoft-adcs-certificates/): This quick guide will give you step-by-step instructions on how to configure Apache HTTPD on Linux with TLS (SSL) using an x.509 certificate issued from a Microsoft Active Directory Certificate Services (ADCS) PKI environment.  We will cover two methods of achieving this both of which have very different levels of complexity and real cost: - [Digital Certificate Management for Growing Businesses](https://revocent.com/digital-certificate-management-growth/): As your business expands, so does the complexity of managing certificates. What starts as a few TLS or authentication certificates quickly becomes a tangled web of renewals, audits, and platform-specific procedures. Without a reliable digital certificate management system, IT teams struggle to keep up—introducing risk, inefficiency, and compliance gaps. - [Certificate Auto-Enrollment of Linux/MacOS End Points for 802.1x EAP-TLS](https://revocent.com/certificate-auto-enrollment-of-linux-mac-end-points-for-802-1x-eap-tls/): The 802.1x IEEE standard provides identity-based access control at the network edge. When implemented with EAP-TLS and X.509 certificates it can provide excellent security and access control at the network port level. This document provides an overview of 802.1x and how to provide the required X.509 certificates on Linux/Mac end-points using automatic provisioning (auto-enrollment) from a Microsoft ADCS PKI. - [How To Configure GlassFish With Fully Managed TLS Certificates in JKS](https://revocent.com/how-to-configure-glassfish-with-fully-managed-tls-certificate-in-jks/): GlassFish is an open source Java application server from Eclipse typically run on Red Hat Enterprise Linux (RHEL), CentOS, Ubuntu Server, MacOS, and Windows Server. This guide will walk you through the steps of configuring a GlassFish server to use an X.509 certificate created from Microsoft ADCS (PKI). GlassFish uses a certificate to provide secure TLS (formerly SSL) communications via HTTPS.  GlassFish requires the certificate to be in a Java Key Store (JKS) file. - [Compliance Automation for PKI: Stay Secure and Meet Regulations](https://revocent.com/compliance-automation-pki-management/): Compliance automation is essential for organizations managing digital certificates across complex environments. Meeting audit requirements manually especially in regulated industries like healthcare, finance, and government, often leads to missed expirations, inconsistent policies, and failed audits. - [Digital Certificate Management: Gaining Control of Your PKI Landscape](https://revocent.com/digital-certificate-management-and-lifecycle-management/): Digital certificates play a central role in enterprise security, enabling encryption, authentication, and trust between systems. However, organizations often lack visibility into where these certificates are deployed, when they expire, and whether they meet internal security policies. Without a centralized certificate management platform, you risk outages, compliance failures, and security breaches. - [Certificate Management: Fixing the Platform Puzzle](https://revocent.com/certificate-management-multiple-devices/): Managing digital certificates across enterprise systems is a critical yet complex challenge. Security teams must track, renew, and secure certificates across Windows, Linux, and macOS— each with different tools and trust stores. Without a centralized strategy, certificate management becomes inconsistent, fragmented, and prone to error. - [Revoked Certificates: Why Speed Matters for Your Security](https://revocent.com/revoked-certificates-removal-pki/): When a certificate gets compromised, it’s not just an IT concern—it’s a full-blown security emergency. Revoked certificates that stay active for too long give attackers a window to impersonate systems, decrypt traffic, or access critical services. Unfortunately, many businesses delay revocation or rely on outdated manual processes. - [MS-WCCE Automated Solution for MacOS](https://revocent.com/ms-wcce-automated-solution-for-macosx/): Windows systems have long supported Microsoft Windows Client Certificate Enrollment (MS-WCCE) which provides automatic X.509 certificate deployment and renewal with Microsoft Active Directory Certificate Services (ADCS).  Apple's MacOS (MacOS X) systems have no MS-WCCE support or any other built-in automated integration with ADCS.  This is a key reason we created CertAccord© Enterprise. - [Using CertAccord Enterprise to Secure VPN/Network Authentication](https://revocent.com/using-certaccord-enterprise-to-secure-vpn-network-authentication/): One of the more popular uses of CertAccord© Enterprise is to create X.509 Certificates providing ClientAuthentication for Virtual Private Network (VPN) authentication.  Many enterprises are moving from username & password based VPN authentication to X.509 certificate authentication. One of the challenges in this transition is how to create and manage certificates on Linux (Red Hat Enterprise Linux (RHEL), Ubuntu Server, etc) and Macs from Microsoft ADCS PKI environments.  Even more challenging is managing the lifecycle of these certificates and avoiding the trap of manually creation and renewal of certificates. CertAccord Enterprise can solve these problems with its ability to automatically create, renew, and centrally manage certificates on Linux, Mac, and Unix systems from Microsoft ADCS. - [How To Create Trusted X.509 Certificates On Linux](https://revocent.com/how-to-create-x-509-certificates-on-linux/): Creating trusted enterprise certificates on Linux has never been easy, but it can be. - [CertAccord Enterprise 8.0](https://revocent.com/certaccord-enterprise-8-0-release/): CertAccord Enterprise 8.0 by Revocent, Inc., now generally available, features Automatic Product Updates, Automatic Certificate Applier™ Distribution, Multiple Active Directory Domain support, Enterprise File Permission Configuration for Certificates, and many other improvements. - [How To Automate the Creation of 802.1X wpa_supplicant.conf on Linux With Microsoft PKI](https://revocent.com/how-to-automate-the-creation-of-802-1x-wpa_supplicant-conf-on-linux-with-microsoft-pki/): When it comes to secure network access in Linux environments, 802.1X and wpa_supplicant are fundamental components. The ability to automate the creation of the wpa_supplicant.conf file, a crucial element of these systems, can greatly enhance their functionality and efficiency. In this context, the role of X.509 certificates becomes crucial, providing reliable, secure authentication for 802.1X connections. - [Streamlining Certificate Configuration in 802.1X wpa_supplicant.conf on Linux](https://revocent.com/streamlining-certificate-configuration-in-802-1x-wpa_supplicant-conf-on-linux/): In the realm of Linux networking, understanding the 802.1X protocol, wpa_supplicant, and the vital role of X.509 certificates is crucial for enhancing network security. As part of this article, we delve into the importance of the wpa_supplicant.conf file, its manual configuration, and the significance of automation. Specifically, we underscore how critical X.509 certificates are in this context. - [MacOS Certificate Auto Enrollment With Microsoft CA](https://revocent.com/macos-x-certificate-auto-enrollment-with-microsoft-ca/): There is no free MacOS (MacOS X) "client" which provides Auto Enrollment or integrates with the Microsoft PKI like the one built into Microsoft Windows.   However, there are commercial options which provide very similar abilities, one in particular which is actually easy to install, use, and won't blowup your budget. - [Why Self-Signed Certificates Are Evil And Alternatives That Are Good](https://revocent.com/why-self-signed-certificates-are-evil/): Self-signed X.509 digital certificates are often used inside enterprises of all sizes on devices and application servers which use HTTPS.  Its often so common place in some enterprises that its easy to forget self-signed certificates are evil.  Maybe not evil in a deliberate sense, but certainly in an effective manner.  Self-signed certificates often lurk in an enterprise and are neglected until used to compromise security which results in serious breaches and damages. - [Linux Certificate Auto Enrollment With Microsoft CA](https://revocent.com/linux-certificate-auto-enrollment-with-microsoft-ca/): There is no free Linux "client" which provides Auto Enrollment of X.509 certificates or integrates with the Microsoft PKI like the Auto Enrollment built into Microsoft Windows.   However, there are commercial options which provide very similar abilities, one in particular which is actually easy to install, use, and won't blowup your budget. - [Automating X.509 Certificate Application Integration with CertAccord Certificate Appliers](https://revocent.com/automating-x-509-certificate-application-integration-with-certaccord-certificate-appliers/): Automatically creating and renewing X.509 certificates on Linux, Mac, and Windows from Microsoft ADCS PKI is simple and quick when using CertAccord© Enterprise. You can take that a step further and automatically integrate certificates with the applications that use them using Certificate Appliers™. This ability allows you to scale your certificate management system by removing manual processes resulting in faster deployments, fewer errors, and a much improved security posture. - [CertAccord Enterprise 7.0](https://revocent.com/certaccord-enterprise-7-0/): CertAccord Enterprise 7.0 by Revocent, Inc. provides improved automated deployments of X.509 Machine Identity Certificates between Microsoft ADCS PKI and Linux/Mac endpoints. Additionally this release features deeper integration with Microsoft ADCS with the support of certificate revocation and numerous improvements to the CertAccord Enterprise Management Console to improve ease of use and deliver additional functionality. - [How To Configure CertAccord When IP/DNS Is Not Accurate](https://revocent.com/how-to-configure-certaccord-when-ip-dns-is-not-accurate/): CertAccord© Enterprise provides automated X509 Certificate Lifecycle Management between PKI platforms like Microsoft ADCS and endpoints running Linux, MacOS, and Windows. The typical CertAccord setup uses DNS to identify endpoints with the CertAccord Enterprise Agent.  The DNS information is used to establish the trusted hostname of an endpoint in order to create its product certificate and identity.  In some environments the DNS information is not accurate because its not up-to-date or because the endpoint IP address is dynamic.  This can occur when systems are located on remote networks and use some form of dynamic IP assignment such as DHCP, NAT, or VPN. - [Revocent Founder Mike Cooper Talks About CertAccord’s Origin](https://revocent.com/revocent-founder-mike-cooper-talks-about-certaccords-origin/): Revocent Founder Mike Cooper was a special guest on The PKI Guy's Office Hours where he discussed how our CertAccord Enterprise product was thought up. We use the term "special" because Mike doesn't appear in the show until about 35min in. Saving the best for last? :) - [Moving past the madness of manually updated X.509 certificates](https://revocent.com/moving-past-the-madness-of-manually-updated-x-509-certificates/): Many organizations rely on Microsoft ADCS for their PKI, but often use manual processes to provide service to all their platforms.  Read more about this "madness" in our guest blog post on Help Net Security. - [Overcoming the Challenge of Shorter Certificate Lifespans](https://revocent.com/overcoming-the-challenge-of-shorter-certificate-lifespans/): In August 2019, Google introduced CA/Browser (CA/B) Forum Ballot SC22 to reduce Transport Layer Security (TLS) certificate validity periods to one year. After much discussion and thousands of comments — mostly in opposition — the ballot failed and certificate maximum lifetimes remained at two years. Or so we thought. Even though shorter certificates enhance ecosystem security – and the lifespans are steadily getting shorter — the overall consensus at the time was that shorter certificates would put too much burden on overworked IT teams. - [5 Key Takeaways from Our Certificate Management Tech Talk](https://revocent.com/5-key-takeaways-from-our-certificate-management-tech-talk/): An enterprise certificate authority (CA) is a vital element of the modern IT ecosystem. It provides the security foundation for all your users, devices, and applications. You can establish who’s trusted, authenticate their validity, and communicate securely using encryption. - [Join our Tech Talk with Futurex – Learn how to unify certificate management](https://revocent.com/join-our-tech-talk-with-futurex-learn-how-to-unify-certificate-management/): With a combination of Microsoft Active Directory Certificate Services (ADCS) and Revocent CertAccord Enterprise you can automate certificate provisioning and renewal across your entire network. Now in a Tech Talk on Wednesday Sept. 16 you can learn how to take this a step further by taking advantage of a FIPS 140-2 Level 3 validated platform for key management from Futurex. - [Video: CertAccord Enterprise Management Console Demo v6.0](https://revocent.com/video-certaccord-enterprise-management-console-demo-v6-0/): This demonstration covers the CertAccord Enterprise Management Console. - [CertAccord™ Enterprise 6.0](https://revocent.com/certaccord-enterprise-6-0/): With the release of CertAccord™ Enterprise 6.0 from Revocent, managing certificates and policies, registering devices or changing settings just became easier and more intuitive via the browser-based CertAccord Management Console. - [Crypto-agility is critical to your company’s security](https://revocent.com/crypto-agility-is-critical-to-your-companys-security/): To achieve long-term data protection in today’s fast-changing and uncertain world, companies need the ability to respond quickly to unforeseen events. Threats like quantum computing are becoming reality while cryptographic algorithms are subject to decay or compromise. Without the ability to identify, manage and replace vulnerable keys and certificates quickly and easily – in other words crypto-agility – companies are at risk. - [Here’s how CertAccord Enterprise helped solve the expiring certificate problem for a power company](https://revocent.com/certaccord-enterprise-expiring-certificate-power-company/): To solve this problem, one of the nation’s top 5 largest power utilities recently selected Revocent’s CertAccord Enterprise to automate its Public Key Infrastructure (PKI) management. This utility runs its own PKI using Microsoft Active Directory Certificate Services (ADCS), but was struggling to manage a growing number of non-Microsoft endpoints using manual processes. - [CertAccord Enterprise 5.0 Provides More Customer Requested Features](https://revocent.com/certaccord-enterprise-5-0/): CertAccord Enterprise 5.0 is now available from Revocent.  This release delivers new customer requested features such as the ability to customize X.509 digital certificate subject and subject alternative names, custom Certificate Purposes, and many other improvements. - [Video: Fast and Easy Certificate Creation on Linux from Microsoft ADCS](https://revocent.com/video-fast-and-easy-certificate-creation-on-linux-from-microsoft-adcs/): This demonstration shows how to quickly and easily create X.509 digital certificates on Linux from Microsoft ADCS using the fully automated CertAccord Enterprise solution. - [CertAccord Enterprise 4.12 Adds User Identity Certificate Support](https://revocent.com/certaccord-enterprise-4-12-adds-user-identity-certificate-support/): CertAccord Enterprise 4.12 is now available from Revocent.  This release adds improved support for user identity X.509 digital certificates in addition to the machine (computer) identity support that has been supported since CertAccord was launched.  User identity certificates can be automatically provisioned and renewed from Microsoft ADCS or GlobalSign on end points running Linux, MacOSX, and even non-domain joined Windows devices. - [CertAccord Enterprise 4.11 Provides Key User Requested Features](https://revocent.com/certaccord-enterprise-4-11/): CertAccord Enterprise 4.11  has been released by Revocent and provides key new features requested by enterprise customers including native RPM and DEB packages for Linux, maintenance periods, and Agent CLI improvements. - [CertAccord Enterprise 4.10 Adds Mac Support](https://revocent.com/certaccord-enterprise-4-10-adds-mac-support/): CertAccord Enterprise 4.10  has been released by Revocent and adds support for Apple MacOS X end point devices.  MacOS X devices are now able to integrate with leading PKI platforms such as Microsoft Active Directory Certificate Services (ADCS) and GlobalSign to create and manage X.509 digital certificates easily and automatically. - [CertAccord Enterprise 4.9 Features Major AD Groups Enhancements](https://revocent.com/certaccord-enterprise-4-9-features-major-ad-groups-enhancements/): CertAccord Enterprise 4.9 has been released by Revocent and features major enhancements to Active Directory (AD) Groups and LDAP settings. - [CertAccord Enterprise 4.8 Features Updated Management Console and Certificate Appliers](https://revocent.com/certaccord-enterprise-4-8-features-updated-management-console-and-certificate-appliers/): CertAccord Enterprise 4.8 has been released by Revocent and features a major update to its Management Console GUI and the introduction of Certificate Appliers.  Additionally many new enterprise friendly features have been implemented including Active Directory filtering of User Groups by OU, logging to Windows Event Log on Windows systems, certificate SAN validation settings, and automatic approval of device registrations by role. - [CertAccord Enterprise 4.6 Adds Solaris Support and More](https://revocent.com/certaccord-enterprise-4-6-adds-solaris-support-and-more/): CertAccord Enterprise version 4.6 has been released by Revocent, Inc.  This release adds CertAccord Enterprise Agent support for Oracle Solaris X64 and SPARC.  This allows Solaris systems, along with existing supported platforms Linux and Windows, to integrate with Microsoft Active Directory Certificate Services (ADCS) and offer a single solution for fully automated certificate lifecycle management. - [CertAccord Enterprise 4.4 Adds Windows Support](https://revocent.com/certaccord-enterprise-4-4-adds-windows-support/): CertAccord Enterprise version 4.4 has been released by Revocent, Inc.  This latest stream release adds support for CertAccord Enterprise Agent on Microsoft Windows platforms.  This support allows for a single integrated solution for Windows Auto Enrollment and automatic certificate renewals on Windows 10, Windows Server 2012, and Windows Server 2016. - [CertAccord Enterprise 3.0 Now Available](https://revocent.com/certaccord-enterprise-3-0-now-available/): Revocent has just released version 3.0 of CertAccord Enterprise providing X.509 digital certificate creation and management on Linux from Microsoft ADCS and GlobalSign PKI services.  This major release provides improved integration with Active Directory (AD) including user authentication and user access control to enterprise digital certificates. - [Revocent and Securely Partner To Deliver Complete Certificate Management Solution](https://revocent.com/revocent-and-securely-partner-to-deliver-complete-certificate-management-solution/): Revocent, Inc. and Securely Ltd today announced their partnership to deliver a complete Digital Certificate Management solution for enterprise customers. Revocent's CertAccord Enterprise product is an ideal solution for integrating Linux with Microsoft PKI environments. Securely's C-View product is an extensive Certificate Management solution which provides monitoring, alerting, and reporting of Microsoft PKI environments. The new partnership will provide customers with a comprehensive solution to certificate management in Microsoft PKI environments. - [Reviewed: Easy certificate management for Linux (InfoWorld)](https://revocent.com/reviewed-easy-certificate-management-for-linux-infoworld/): A very positive review of CertAccord Enterprise by Roger A Grimes from InfoWorld can be found here. - [CertAccord Enterprise 1.0 beta](https://revocent.com/certaccord-enterprise-1-0-beta/): Our flagship CertAccord Enterprise product is now in beta test.  This version supports the ability for Linux systems to integrate with Microsoft Certificate Authorities.  Linux systems can now request X.509 certificates from a Microsoft CA in a simple, fast, and automated manner.  Certificates are automatically renewed throughout their lifetime without any human intervention. ## Pages - [PKI Resources](https://revocent.com/pki-resources/): PKI Resources - [GDPR Policy](https://revocent.com/gdpr-policy/): Effective Date: January 1, 2023 - [Case Studies](https://revocent.com/case-studies/): DZ BANK AG is the head institute of one of the largest banks in Germany and they had a big problem. They needed to deploy and maintain X.509 certificates to thousands of Linux servers to meet regulatory compliance requirements and to improve security in an effective manner. They had an existing Microsoft Public Key Infrastructure (PKI) implementation of Active Directory Certificate Services (ADCS) which worked fine for Windows based systems, but lacked integration with other platforms like Linux. Revocent's CertAccord Enterprise solution solved this problem resulting in meeting regulatory compliance requirements, improved security posture, lower costs, and freeing IT staff to invest in other value added services. - [How DZ BANK Automated Linux Certificate Lifecycle Management With Microsoft PKI](https://revocent.com/case-study-finance-automated-dz-bank-certificate-management/): DZ BANK AG is the head institute of one of the largest banks in Germany and they had a big problem. They needed to deploy and maintain X.509 certificates to thousands of Linux servers to meet regulatory compliance requirements and to improve security in an effective manner. They had an existing Microsoft Public Key Infrastructure (PKI) implementation of Active Directory Certificate Services (ADCS) which worked fine for Windows based systems, but lacked integration with other platforms like Linux. Revocent's CertAccord Enterprise solution solved this problem resulting in meeting regulatory compliance requirements, improved security posture, lower costs, and freeing IT staff to invest in other value added services. - [What is a Self Signed Certificate and How Does it Work](https://revocent.com/support/resources/what-is-a-self-signed-certificate-and-how-does-it-work/): A self signed certificate is an X.509 certificate that is not signed by a trusted Certificate Authority but rather is signed by its own private key. - [Technical Resources](https://revocent.com/support/resources/): Revocent provides free resources to the community to help explain key concepts of PKI including PKI best practices and PKI certificate management solutions. - [What is a SAN Certificate and How Does it Work](https://revocent.com/support/resources/what-is-san-certificate-and-how-does-it-work/): A SAN Certificate is an X.509 certificate which contains one or more names used to identify a computer by hostname or a user by their email address. - [Schedule a Demo](https://revocent.com/schedule-a-demo/): The best way to see how CertAccord Enterprise automates PKI certificate management is to schedule a demo. Learn how CertAccord Enterprise works, how it integrates quickly into your existing Microsoft PKI, and how it can automate your machine identity life-cycle management. - [Why Revocent](https://revocent.com/why-revocent/): Because automating your PKI user and machine identities is critical to securing your enterprise. - [Purchase RTU](https://revocent.com/purchase-rtu/): By clicking the Buy Now button you will be purchasing a single RTU for certaccord. Your license will be emailed to you within 3 business days. - [CertAccord Enterprise Demos](https://revocent.com/products/certaccord-enterprise/certaccord-enterprise-demos/): These video demos will highlight the capabilities of CertAccord Enterprise to quickly and easily create X.509 digital certificates at scale on Linux, Mac, Unix, and Windows from Microsoft ADCS. - [White Paper](https://revocent.com/white-paper/): Download the Whte Paper - [Downloads](https://revocent.com/download/): Access to CertAccord Enterprise downloads is restricted to registered users who have been verified by Revocent.  To request access, please register and then email admin@revocent.com to request access. - [About](https://revocent.com/about-revocent/): Revocent©, based in Silicon Valley, provides best-in-class PKI certificate management solutions to leading enterprises in the United States, Europe, and Australia. CertAccord© Enterprise is full life-cycle certificate management solution trusted by leading enterprises in banking/finance, power utilities, technology companies, and leading research institutions. - [Contact](https://revocent.com/contact/): Phone: +1 408-638-9323Email: info@revocent.comHQ: San Jose, CA USA - [Partners](https://revocent.com/partners/): For more than 40 years, Futurex has been a trusted provider of hardened, enterprise-class data security solutions. More than 15,000 organizations worldwide have used Futurex's innovative hardware security modules, key management servers, and cloud HSM solutions to address mission-critical data encryption and key management needs. - [Support](https://revocent.com/support/): Supporting our customers is part of our DNA.  If you need help installing or using our products, please email support@revocent.com - [Products](https://revocent.com/products/): CertAccord Enterprise integrates your existingCertificate Authorities with Linux, Macand UNIX systems. Learn More - [Home](https://revocent.com/): Find out how to quickly and easily make Linux, Unix and macOS systems part of your Microsoft PKI - [Schedule Consultation](https://revocent.com/schedule-consultation/): Schedule A Consultation - [Case Study Power Utility](https://revocent.com/case-study-utility-power-utility-certificate-automation/): Power utility companies have a critical need to protect just about everything in their entire infrastructure from cyberattacks. There's no lack of rogue actors and nation states looking for ways into the US power grid whether for profit or to disrupt operations. Like many other companies and industries, utilities often base their core IT infrastructure on Microsoft Windows Server in conjunction with Unix and Linux based platforms. For a strong security posture, many utilities manage their own Public Key Infrastructure (PKI) often based on Microsoft Active Directory Certificate Services (ADCS) to support a broad range of security needs. - [How CertAccord Enterprise Works](https://revocent.com/products/certaccord-enterprise/certaccord-enterprise-how-it-works/): Automate Microsoft ADCS or GlobalSign certificate creation and renewal across your network - [CertAccord Enterprise](https://revocent.com/products/certaccord-enterprise/): Extend certificate enrollment and automatic renewal across your entire network to Linux/Mac - [CertAccord Announcements Signup](https://revocent.com/signup/): Your time and privacy are important.  We will only send you information about CertAccord and you can opt out at any time. - [CertAccord Enterprise Supported Platforms](https://revocent.com/products/certaccord-enterprise/certaccord-enterprise-supported-platforms/): CertAccord Enterprise Agent currently supports the following platforms: - [Password Reset](https://revocent.com/password-reset/) - [Account](https://revocent.com/account/) - [Logout](https://revocent.com/logout/) - [Members](https://revocent.com/members/) - [Register](https://revocent.com/register/) - [Login](https://revocent.com/login/) - [User](https://revocent.com/user/) - [Terms of Service](https://revocent.com/terms-of-service/): Please read these Terms of Service (“Terms”, “Terms of Service”) carefully before using the https://www.revocent.com website (the “Service”) operated by Revocent, Inc. ("Revocent", “us”, “we”, or “our”). - [Privacy Policy](https://revocent.com/privacy-policy/): Revocent has the utmost respect for our customers’ privacy. In no way will we violate this philosophy. We will not release any information gathered about our customers. - [Sitemap](https://revocent.com/sitemap/): Sitemap PagesAboutAccountCase StudyCertAccord Announcements SignupContactDownloadsHomeLoginLogoutMembersPartnersPassword ResetPrivacy PolicyProductsCertAccord EnterpriseCertAccord Enterprise DemosCertAccord Enterprise Supported PlatformsHow CertAccord Enterprise WorksRegisterSchedule ConsultationSitemapSupportTerms of ServiceUserWhite Paper ## Templates - [Info boxes](https://revocent.com/fl-builder-template/info-boxes/) - [Blog sidebar](https://revocent.com/fl-builder-template/blog-sidebar/) - [Sidebar for Products page](https://revocent.com/fl-builder-template/sidebar-for-products-page/) - [About Layout](https://revocent.com/fl-builder-template/about-layout/) - [Home Layout](https://revocent.com/fl-builder-template/home-layout/) - [left text right photo](https://revocent.com/fl-builder-template/left-text-right-photo/) - [Header Row with Purple Overlay](https://revocent.com/fl-builder-template/header-row-with-purple-overlay/) - [Purple overlay form home](https://revocent.com/fl-builder-template/purple-overlay-form-home/)