Managed PKI
Managed PKI with PRIMARCH
We build, operate, and maintain your dedicated PKI hierarchy. You retain full control over your certificate chain - including the right to take over the complete key material at any time.
Your certificate chain
└─ CN=Nexilon PRIMARCH Issuing CA - Your Company G1, O=Nexilon GmbH
└─ CN=vpn.yourcompany.com
What you get
Dedicated Root CA. No shared infrastructure. Your PKI hierarchy belongs to you - we merely operate it on your behalf.
Certificates on demand. SSL/TLS for reverse proxies, DPI certificates for firewalls, client certificates for VPN authentication, and more.
Secure key custody. Root CA key material is encrypted and kept offline. Access only for authorised certificate operations.
Trust distribution. We assist with distributing your root CA certificate via GPO, MDM, or manual configuration.
No vendor lock-in. Guaranteed.
Unlike traditional managed PKI providers, PRIMARCH gives you the complete key material at any time - including the root CA, intermediate CAs, and the entire certificate database.
Should you decide to run your PKI in-house, we hand over everything - encrypted, documented, and without reissuance. Your existing certificates and the entire chain of trust remain valid.
Typical use cases
- SSL termination and deep packet inspection on FortiGate and other NGFWs
- Client certificates for VPN authentication (IPSec, SSL-VPN, WireGuard)
- RADIUS/802.1X authentication on the corporate network
- Internal web services and reverse proxy protection
- S/MIME certificates for email encryption and signing
- Code signing for internal scripts and software distribution