Skip to main content
Requestsissue · renew · revokeDuoKey issuersone console · unified auditLet's Encryptpublic ACMEAWS Private CAACM PCAAzure Key Vault CAcloud CAGoogle Cloud CAScloud CASectigocommercialDigiCert / QuoVadisCertCentralCloudflareorigin / edgeInternal CAvault-backed
Front public, cloud and internal CAs from one console — requests, renewals and revocations flow through a single audit trail. (TuringSign and Venafi coming soon.)
Applies to:
DuoKey Cockpit v2External / cloud / internal CAsUnified issue · renew · revoke

What an issuer is​

An issuer is a connector to a certificate authority — public, cloud-hosted, enterprise or internal. Instead of managing each CA in its own portal, you register it once as an issuer, and requests, renewals and revocations flow through DuoKey with a single audit trail and permission model.

Every connector implements the same operations: test-connection, issue, renew, revoke, and — for ACME-based issuers — account registration.

Supported issuers​

IssuerBackendStatus
Let's EncryptPublic ACME CA (incl. http-01 challenge handling)Available
AWS Private CAAWS ACM Private CAAvailable
Azure Key Vault CAAzure Key Vault certificate CAAvailable
Google Cloud CASGoogle Certificate Authority ServiceAvailable
SectigoCommercial CAAvailable
DigiCertDigiCert CertCentralAvailable
QuoVadisDigiCert subsidiary (shared connector)Available
CloudflareOrigin / edge CAAvailable
Volkswagen Group PKIPPCS mTLS enterprise PKIAvailable
Internal CAA vault-backed CA operated inside DuoKeyAvailable
TuringSignTuringSign trust servicesAvailable
KeyfactorKeyfactor / EJBCA enterprise CA engineAvailable
Microsoft AD CS (NDES)SCEP enrollment against Active Directory Certificate ServicesAvailable
AppViewXAppViewX CERT+ certificate lifecycle platformAvailable
Nexus Certificate ManagerNexus Smart ID CMAvailable
VenafiVenafi Trust Protection PlatformComing soon
Coming soon

Venafi integration is in progress. It appears in the console, but is not yet available to select. This page will document its configuration once it ships.

Internal CA vs external issuers​

  • Use the Internal CA (or the CA management hierarchy) when you want DuoKey to be the certificate authority, with keys in your vault / HSM.
  • Use an external issuer when certificates must be signed by a public CA (for browser-trusted TLS) or by a corporate / cloud CA you already operate.

Both paths converge on the same certificate lifecycle, deployment targets and revocation tooling.

Registering an issuer​

1

Create the issuer

Add an issuer of the appropriate type and provide its credentials — an API key, a cloud role / service principal, or an ACME account, depending on the backend.

2

Test the connection

Run test-connection to confirm the credentials and endpoint before relying on it.

3

Register the account (ACME only)

For ACME issuers such as Let's Encrypt, register the ACME account so orders can be placed.

4

Issue through the issuer

Request certificates against the issuer; renewals and revocations are driven through the same connector.

API reference​

Registering an issuer, testing its connection, registering an ACME account, and issuing, renewing or revoking through it are all available programmatically through the platform API.

API reference
Detailed API endpoints are documented separately in the Developer Docs → PKI API.