Skip to main content
Version: 2.7 (Current)

πŸ“‹ Introduction

SecTrail CM offers three main integration categories to automate every phase of the certificate lifecycle: Certificate Authority (CA) integrations, System Integrations, and ITSM Integration.

Integration Types​

Certificate Authority (CA) Integrations​

CA integrations automate certificate acquisition and renewal processes. SecTrail CM works seamlessly with both public and private certificate authorities, fully automating certificate requests, approval processes, and certificate acquisition.

Key Features:

  • Automatic certificate request and approval process
  • Automatic renewal
  • Multi-CA support
  • Template-based request management
  • API-based secure communication

Supported CA Types:

CA TypeIntegrations
Public CADigiCert, GlobalSign
Private CAMicrosoft ADCS, HashiCorp Vault, AWS Private CA
ACME ClientLet's Encrypt, Let's Encrypt Staging, ZeroSSL, Buypass, Buypass Staging, SSL.com RSA, SSL.com ECC, Google Trust Services, Google Trust Services Staging, DigiCert
ACME ServerSecTrail CM ACME Server (for clients such as Certbot, acme.sh, Caddy, Traefik, win-acme)
EST ServerSecTrail CM EST Server (for network devices, IoT, and embedded systems - RFC 7030)

System Integrations​

System integrations automate the deployment and management of certificates obtained from CAs to target systems. They establish secure connections to load balancers, firewalls, web servers, and application servers using an agent-less architecture to automatically perform certificate exchanges.

Key Features:

  • Agent-less architecture
  • Secure protocols (SSH, WinRM, HTTPS API)
  • Post-deployment verification with automatic rollback on mismatch
  • Deployment via DDA for directly unreachable networks
  • Detailed audit logs

Supported System Categories:

CategoryIntegrations
Load BalancerF5 BIG-IP, Citrix NetScaler
FirewallPalo Alto, PaloAlto Panorama, Fortinet FortiWeb, FortiGate, FortiManager
Web ServerNGINX, Apache, IIS
App ServerTomcat, Java Keystore
Certificate StoreWindows Trust Store, Azure Key Vault

Vault / PAM Integrations​

Vault / PAM integrations enable dynamically reading user passwords from a central vault when connecting to target systems and securely storing certificates. Passwords are not stored statically in SecTrail CM; they are retrieved from the relevant vault at the moment of each operation.

Key Features:

  • Dynamic password retrieval (no static password storage)
  • Automatic alignment with password rotation on the CyberArk side
  • Central storage of certificates in the vault
  • Centralized access control and logging

Supported Tools:

CategoryIntegrations
PAMCyberArk

ITSM Integration​

ITSM integration connects the certificate lifecycle to enterprise service management processes. It automatically opens tickets for expiring certificates, reads renewal requests created on the ITSM side to trigger a fully automated signing workflow, and keeps ticket status synchronized in both directions.

Key Features:

  • Automatic ticket creation and assignment to the owner
  • Fully automated signing workflow from renewal requests
  • Bidirectional status synchronization
  • Field mapping for ITSM-specific schema support

Supported Tools:

CategoryIntegrations
ITSMITSM Integration (ServiceNow, Jira, Remedy, Maximo)