Skip to main content
Devices & workloadsservers · gatewaysKubernetes · KMIP clientsENROLLMENT PROTOCOLSenrolACMERFC 8555ESTRFC 7030SCEPRFC 8894CMPRFC 4210cert-managerKubernetesKMIPOASIS 2.1signDuoKey CAissue / renew
Devices and workloads enrol over the protocol they already speak — the CA issues and renews their certificates automatically.
Applies to:
DuoKey Cockpit v2ACME · EST · SCEP · CMPcert-manager · KMIP 2.1

Overview​

Beyond the manual request-and-approval workflow, DuoKey exposes the standard enrollment protocols so clients can obtain and renew certificates without human steps. Each protocol has a public protocol endpoint (what clients call) and admin configuration in the Cockpit (bound to a CA and gated by permissions).

ProtocolStandardTypical clients
ACMERFC 8555certbot, acme.sh, Kubernetes cert-manager, Caddy
ESTRFC 7030Routers, gateways, IoT devices
SCEPRFC 8894Network devices, MDM-managed endpoints
CMPRFC 4210 / 9483Industrial and operator PKIs
cert-managerKubernetesKubernetes workloads (external issuer)
KMIPOASIS KMIP 2.1KMIP clients (key / certificate objects)

ACME (RFC 8555)​

A full ACME server per CA, covering the complete account, order, authorization, challenge, finalize, download and revoke flow. Point any ACME client (or cert-manager's ACME issuer) at the CA's ACME directory URL — {cockpit-url}/api/pki/acme/{ca-id}/directory.

Real domain-control validation

http-01 challenges are validated for real: the ACME server fetches http://{domain}/.well-known/acme-challenge/{token} back from the requester and checks the key authorization, exactly like a public CA would. There is no silent auto-approval — an internal or trusted-network CA can opt into skipping this check for lab use, but it is off by default.

Using ACME with Kubernetes cert-manager​

The most direct way to get DuoKey-issued, auto-renewing TLS certificates into a Kubernetes cluster today is cert-manager's built-in ACME issuer type, pointed at your CA's ACME directory. This has been verified end-to-end against a real cluster: cert-manager both issuing and renewing a certificate through this endpoint.

Prerequisites

  • ACME enabled on the issuing CA (Cockpit → PKI → ACME → Configure)
  • cert-manager installed in the cluster
  • An ingress controller installed (cert-manager's http-01 solver routes the challenge through it)
  • The requested domain resolves to somewhere the Cockpit can reach — a public address, or a private-network address if the Cockpit runs inside your network (loopback and link-local targets are always rejected)
1

Register a ClusterIssuer

cluster-issuer.yamlYAML
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: dke-cockpit-acme
spec:
acme:
  server: https://{cockpit-url}/api/pki/acme/{ca-id}/directory
  email: [email protected]
  privateKeySecretRef:
    name: dke-cockpit-acme-account-key
  solvers:
    - http01:
        ingress:
          ingressClassName: nginx
2

Request a certificate

certificate.yamlYAML
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: example-tls
namespace: default
spec:
secretName: example-tls
dnsNames:
  - app.example.com
issuerRef:
  name: dke-cockpit-acme
  kind: ClusterIssuer
  group: cert-manager.io
3

Renewal is automatic

cert-manager reissues before expiry (its default is two-thirds of the certificate's lifetime, configurable via renewBefore), driving the exact same order → challenge → finalize flow as the initial issuance — no manual intervention required.

EST (RFC 7030)​

Enrollment over Secure Transport, supporting the standard cacerts, simpleenroll, simplereenroll, serverkeygen and csrattrs operations for devices and gateways.

SCEP (RFC 8894)​

Simple Certificate Enrollment Protocol with configurable profiles for classic SCEP clients such as network devices and MDM-managed endpoints.

CMP (RFC 4210 / 9483)​

Certificate Management Protocol with named aliases, transaction tracking and per-alias metrics, for industrial and operator PKIs.

Kubernetes cert-manager (native external issuer)​

DuoKey also defines a native cert-manager external-issuer type (API group dke.duokey.com), for a tighter CSR-relay integration without an intermediate ACME layer — cert-manager submits CSRs directly and DuoKey returns signed certificates.

Rolling out

This integration is still on its way to general availability — reach out to your DuoKey contact for current status. The ACME method above is the supported way to use cert-manager with DuoKey today.

KMIP 2.1 server​

DuoKey can act as a KMIP server, exposing key / certificate objects and operations to KMIP clients.

Unified endpoint lifecycle​

All protocol endpoints (EST / SCEP / ACME / CMP / KMIP) share a common endpoint lifecycle — deploy, start, pause, stop — with health and metrics, so you can operate them consistently.

API reference
Detailed API endpoints are documented separately in the Developer Docs → PKI API.
DirectoryendpointsNew accountregister keyNew orderidentifiersChallengehttp-01 / dns-01Finalizesubmit CSRCertificatedownload
ACME (RFC 8555): a client validates control of an identifier, submits a CSR, then downloads the issued certificate — fully automated.