π Introduction
SecTrail CM offers three main integration categories to automate every phase of the certificate lifecycle: Certificate Authority (CA) integrations, System Integrations, and ITSM Integration.
Integration Typesβ
Certificate Authority (CA) Integrationsβ
CA integrations automate certificate acquisition and renewal processes. SecTrail CM works seamlessly with both public and private certificate authorities, fully automating certificate requests, approval processes, and certificate acquisition.
Key Features:
- Automatic certificate request and approval process
- Automatic renewal
- Multi-CA support
- Template-based request management
- API-based secure communication
Supported CA Types:
System Integrationsβ
System integrations automate the deployment and management of certificates obtained from CAs to target systems. They establish secure connections to load balancers, firewalls, web servers, and application servers using an agent-less architecture to automatically perform certificate exchanges.
Key Features:
- Agent-less architecture
- Secure protocols (SSH, WinRM, HTTPS API)
- Post-deployment verification with automatic rollback on mismatch
- Deployment via DDA for directly unreachable networks
- Detailed audit logs
Supported System Categories:
| Category | Integrations |
|---|---|
| Load Balancer | F5 BIG-IP, Citrix NetScaler |
| Firewall | Palo Alto, PaloAlto Panorama, Fortinet FortiWeb, FortiGate, FortiManager |
| Web Server | NGINX, Apache, IIS |
| App Server | Tomcat, Java Keystore |
| Certificate Store | Windows Trust Store, Azure Key Vault |
Vault / PAM Integrationsβ
Vault / PAM integrations enable dynamically reading user passwords from a central vault when connecting to target systems and securely storing certificates. Passwords are not stored statically in SecTrail CM; they are retrieved from the relevant vault at the moment of each operation.
Key Features:
- Dynamic password retrieval (no static password storage)
- Automatic alignment with password rotation on the CyberArk side
- Central storage of certificates in the vault
- Centralized access control and logging
Supported Tools:
| Category | Integrations |
|---|---|
| PAM | CyberArk |
ITSM Integrationβ
ITSM integration connects the certificate lifecycle to enterprise service management processes. It automatically opens tickets for expiring certificates, reads renewal requests created on the ITSM side to trigger a fully automated signing workflow, and keeps ticket status synchronized in both directions.
Key Features:
- Automatic ticket creation and assignment to the owner
- Fully automated signing workflow from renewal requests
- Bidirectional status synchronization
- Field mapping for ITSM-specific schema support
Supported Tools:
| Category | Integrations |
|---|---|
| ITSM | ITSM Integration (ServiceNow, Jira, Remedy, Maximo) |