This page is a scaffold stub. Content coming soon.
Controlled Certificate Consumption
Self-Service Requests allow certificate consumers to initiate certificate requests within a governed framework. This helps organizations decentralize routine certificate demand while preserving centralized PKI policy. Application teams, infrastructure teams, DevOps teams, and other authorized users can request certificates without requiring direct access to the underlying certificate authority. KryptoVault therefore separates certificate consumption from CA administration.Policy-Driven Request Model
Self-service certificate requests can be aligned with organizational certificate policies. A request can be governed according to the certificate purpose, issuer, cryptographic requirements, approval model, certificate validity, and operational destination. This helps ensure that delegated certificate requests remain consistent with enterprise PKI standards.Issuer Integration
Self-service requests are connected with the KryptoVault issuer framework. Once a request is approved and ready for issuance, it can be routed to a supported issuer such as:- ACME
- Microsoft AD CS through KryptoVault Gateway
- Vault PKI
Request Approval
KryptoVault can apply approval controls before a certificate request proceeds to issuance. Approval introduces governance between certificate demand and certificate creation. This is particularly valuable where certificate issuance must be reviewed because of:- Security requirements
- Business ownership
- Sensitive domains
- Privileged applications
- Production environments
- Regulatory requirements
Request Lifecycle
Self-service requests move through a controlled lifecycle from submission to final outcome. The lifecycle provides visibility into whether a request is awaiting action, approved, rejected, or completed through certificate issuance. This centralized request model helps organizations maintain accountability for certificate consumption without requiring manual tracking outside the platform.Certificate Issuance Integration
Approved self-service requests can flow directly into the CSR and certificate issuance process. KryptoVault can coordinate certificate request generation, issuer communication, signing, and certificate onboarding as part of the same lifecycle. This provides continuity between the business request and the cryptographic issuance operation.Inventory Integration
Certificates issued through self-service requests become part of the centralized KryptoVault certificate inventory. Once issued, they can participate in the same management model as other certificates. This includes:- Expiration monitoring
- Lifecycle management
- Cryptographic analysis
- Risk assessment
- Certificate-store association
- Issuer tracking
- Renewal management
Certificate Store Integration
Self-service certificates can be associated with the appropriate certificate store. This maintains operational context for the certificate and supports downstream lifecycle activities. The store relationship helps connect the request with the application, environment, service, or infrastructure where the certificate will be managed.Private Key Integration
Where the issuance workflow includes key generation or key association, KryptoVault can maintain the relationship between the resulting certificate and its corresponding private key. This ensures that self-service issuance remains connected to the broader cryptographic asset-management model. Private-key access can remain restricted even when certificate request capabilities are delegated to a wider user population.Delegated PKI Operations
Self-Service Requests help organizations distribute routine certificate operations without distributing PKI administrative privileges. This allows application or infrastructure teams to obtain certificates while certificate authority management, issuer configuration, and sensitive cryptographic controls remain under dedicated administrative ownership. The model supports separation of duties between:- Certificate consumers
- Approvers
- PKI administrators
- Security administrators
- Infrastructure operators