Introduction

true-CA Features

The keyon - true-CA is a standalone, multi-tenant certificate authority that allows you to use multiple CAs on a single server.

Component Overview

overview

Main components are:

Technical Details

The true-CA service runs as an application in IIS and offers a CA web service and an administration web service. The true-CA CAConnector enables its use via the keyon true-Xtender Registration Authority, the keyon true-Xtender CAConnector Service, and the keyon true-Xtender Autoenroll PKI or in a standalonce scenario.

There are plenty of options (by PowerShell scripts) to create new CAs (CA certificate generated as softtoken or in HSM) including certificate blueprints and CRL blueprints. The trueCAAdminUtil provides functionality for further administration.

true-CA Service uses CA certificates which are stored in Windows Certificate Store. This allows the Certificate private key to be stored on a HSM (e.g. for Thales SafeNet HSMs to be used with Safenet KSP, a CNG provider) as well as a Softtoken certificate with the protected key in the file system.

Component Details

overview


Revision #7
Created 2026-06-10 08:10:30 UTC by SITS
Updated 2026-06-10 13:53:40 UTC by SITS