# Enrollment Proxy

# Introduction

[](pdfgenerator=eyJ0aXRsZSI6IFsiRW5yb2xsbWVudCBQcm94eSJdLCAic3VidGl0bGUiOiBbIkludHJvZHVjdGlvbiJdfQ==)
The Enrollment Proxy is a proxy for certificate enrollment protocols, which allows clients to enroll and update X.509v3
certificates via the true-Xtender Registration Authority (RA).

# Purpose of the Application

The Enrollment Proxy provides a standards-based certificate enrollment service for clients that use CMPv2 (Certificate
Management Protocol) or EST (Enrollment over Secure Transport). It acts as an intermediary between certificate
requesters (end entities) and the true-Xtender Registration Authority (RA), performing protocol handling, request
validation, authentication, authorization, and request forwarding.

The separation from the RA is especially useful in distributed networks, as multiple instances can be placed on the
trust boundary and network traffic to the RA can be limited to the Enrollment Proxy.

# Intended Use Cases

- automation of certificate enrollment
- automation of certificate renewal

# Architecture

![diagram](/uploads/images/gallery/2026-09/qGL9d0e73511c2d9eec3d0d2de1016ac4b05cc64acd-content-1.png)