Issuers
Drive external, cloud and internal certificate authorities through one console.
What an issuer is
An issuer is a connector to a certificate authority — public, cloud-hosted, enterprise or internal. Instead of managing each CA in its own portal, you register it once as an issuer, and requests, renewals and revocations flow through DuoKey with a single audit trail and permission model.
Every connector implements the same operations: test-connection, issue, renew, revoke, and — for ACME-based issuers — account registration.
Supported issuers
| Issuer | Backend | Status |
|---|---|---|
| Let's Encrypt | Public ACME CA (incl. http-01 challenge handling) | Available |
| AWS Private CA | AWS ACM Private CA | Available |
| Azure Key Vault CA | Azure Key Vault certificate CA | Available |
| Google Cloud CAS | Google Certificate Authority Service | Available |
| Sectigo | Commercial CA | Available |
| DigiCert | DigiCert CertCentral | Available |
| QuoVadis | DigiCert subsidiary (shared connector) | Available |
| Cloudflare | Origin / edge CA | Available |
| Volkswagen Group PKI | PPCS mTLS enterprise PKI | Available |
| Internal CA | A vault-backed CA operated inside DuoKey | Available |
| TuringSign | TuringSign trust services | Available |
| Keyfactor | Keyfactor / EJBCA enterprise CA engine | Available |
| Microsoft AD CS (NDES) | SCEP enrollment against Active Directory Certificate Services | Available |
| AppViewX | AppViewX CERT+ certificate lifecycle platform | Available |
| Nexus Certificate Manager | Nexus Smart ID CM | Available |
| Venafi | Venafi Trust Protection Platform | Coming soon |
Venafi integration is in progress. It appears in the console, but is not yet available to select. This page will document its configuration once it ships.
Internal CA vs external issuers
- Use the Internal CA (or the CA management hierarchy) when you want DuoKey to be the certificate authority, with keys in your vault / HSM.
- Use an external issuer when certificates must be signed by a public CA (for browser-trusted TLS) or by a corporate / cloud CA you already operate.
Both paths converge on the same certificate lifecycle, deployment targets and revocation tooling.
Registering an issuer
Create the issuer
Add an issuer of the appropriate type and provide its credentials — an API key, a cloud role / service principal, or an ACME account, depending on the backend.
Test the connection
Run test-connection to confirm the credentials and endpoint before relying on it.
Register the account (ACME only)
For ACME issuers such as Let's Encrypt, register the ACME account so orders can be placed.
Issue through the issuer
Request certificates against the issuer; renewals and revocations are driven through the same connector.
API reference
Registering an issuer, testing its connection, registering an ACME account, and issuing, renewing or revoking through it are all available programmatically through the platform API.