Red Hat helps organizations manage certificates as a governed, automated lifecycle—not a recurring fire drill. Red Hat® Certificate System serves as the enterprise public key infrastructure (PKI) foundation. Complemented by Identity Management (IdM), certmonger, and Red Hat Ansible® Automation Platform, teams can issue, renew, revoke, and operate certificates with the speed and consistency today’s environments require.
This overview describes the Red Hat approach: an on-premise or private cloud enterprise certificate authority (CA) designed for automation, standards-based enrollment across diverse workloads, Red Hat Enterprise Linux-integrated lifecycle operations, strict control over keys and infrastructure, and the crypto-agility needed as algorithms evolve.
Enterprise PKI that makes automation the default
Red Hat Certificate System is an enterprise certificate authority platform built on Dogtag PKI with more than 20 years of sustained development. It supports organizations that need to run PKI on their own terms—on premise or in a private cloud—with hardware security module (HSM) support for protected key operations.
Unlike approaches that treat automation as an add-on, Certificate System is built so continuous issuance, renewal, and revocation are part of normal operations. Clients request and renew certificates through standard protocols. Those requests terminate at the CA, which connects to Red Hat Directory Server for identity and policy context and to an HSM where key protection is required. One CA infrastructure can support multiple enrollment methods and client ecosystems, which helps organizations avoid standing up isolated PKI structures for different teams or device types.
A fragmented, manually operated CA model increases outage risk and coordination cost. A consolidated, automation-ready enterprise CA gives security and platform leaders a clearer ownership model, stronger policy control, and a more predictable operating foundation as certificate lifetimes shrink.
Scenario: A global enterprise running customer-facing applications, internal APIs, and shared services across multiple regions needs certificates renewed far more frequently than before. Instead of routing every renewal through tickets and weekend change windows, the organization standardizes the Certificate System as the enterprise CA, connects it to directory-backed identity and policy, and allows automated enrollment for the services that can renew without human intervention. The result is fewer emergency expirations and a CA operating model that scales with renewal demand.
1 enrollment strategy for web, Internet of Things (IoT), operational technology (OT), and enterprise systems
Automation only works when the CA and the workloads speak common languages. Red Hat Certificate System supports the enrollment protocols organizations use across real production estates:
Automated Certificate Management Environment (ACME) for web servers, Kubernetes and container platforms, content delivery networks, and load balancers—using familiar clients such as certbot and cert-manager
Enrollment over Secure Transport (EST) for constrained devices, industrial control systems, and network equipment
Certificate Management over CMS (CMC) and related enterprise enrollment paths for workstations, smart cards, and hybrid environments that still include traditional systems
This breadth lets organizations pursue a unified certificate strategy instead of maintaining separate operational models for each class of endpoint. Web and platform teams can automate with ACME. Operational technology and network teams can enroll devices with EST. Identity and endpoint teams can continue supporting enterprise enrollment paths where required. The business benefits include fewer toolchains, clearer accountability, and less risk that an unowned certificate becomes tomorrow’s outage.
Scenario: A manufacturer needs certificates for plant-floor devices and for the IT systems that connect those devices to enterprise applications. With EST for constrained and industrial systems and ACME for application and web tiers, the same Certificate System CA can support both worlds. Security leaders retain centralized policy and visibility, while local teams automate the renewals that previously depended on organizational knowledge and manual installs.
Lifecycle control from identity to host to the full estate
Enterprise PKI is only half of the solution. Certificates also have to be requested, installed, renewed, and replaced where workloads run. Red Hat extends Certificate System with Red Hat Enterprise Linux capabilities that complete the lifecycle:
Identity Management (IdM) provides integrated PKI with automated certificate enrollment for identity-centric use cases.
certmonger helps Red Hat Enterprise Linux systems track certificate state and renew or replace certificates before expiration becomes an incident.
Red Hat Ansible Automation Platform extends certificate operations across large estates with repeatable, reviewable automation.
Together, these capabilities support a practical operating model: standardize enrollment at the CA, automate renewal on the host, and orchestrate policy and remediation across the estate. That model is especially valuable for organizations standardizing on Red Hat Enterprise Linux, because certificate operations can align with the same management, automation, and support practices already used for infrastructure.
Keep cryptographic control where your business needs it
As certificate operations become continuous, control over PKI becomes a strategic concern. Certificates prove identity. TLS protects data in transit. Signatures protect integrity. If an organization does not control its PKI, it does not fully control the trust architecture that those controls depend on.
Red Hat Certificate System is for organizations that need custody of that trust architecture:
- Deploy on premise or in a private cloud, including environments that require limited external dependency or air-gapped operation.
- Protect keys with customer-managed HSM integration so critical CA key material remains under enterprise governance.
- Retain operational control of policy, approval, and audit evidence to support regulatory and sector expectations.
This matters for government, financial services, healthcare, telecommunications, and other regulated or security-sensitive industries—and for partners selling into those markets. The solution is not “automation or control.” It is automation with control: faster renewal cycles without surrendering the cryptographic anchor of digital identity.
Build crypto-agility into the same automation investment
Shorter certificate lifetimes are not the only change on the horizon. Cryptographic standards continue to evolve, including post-quantum algorithms standardized by National Institute of Standards and Technology (NIST)3. Organizations will need the ability to change algorithms, key sizes, and certificate profiles without redesigning every application. That capability—crypto-agility—depends on the same foundation required for high-frequency renewal: automated enrollment, policy-driven issuance, and reliable replacement across the estate.
Red Hat Enterprise Linux strengthens platform-level crypto-policy and post-quantum readiness, while Red Hat certificate capabilities provide the operational path to issue and renew certificates as profiles change. Dual or hybrid certificate strategies can support transition periods where classical and post-quantum signatures coexist, helping organizations migrate without a single disruptive cutover.
What organizations can achieve with Red Hat certificate capabilities
With Red Hat Certificate System and complementary Red Hat Enterprise Linux certificate lifecycle capabilities, organizations and partners can help customers:
- Reduce outage risk caused by expired or poorly tracked certificates as renewal volume increases.
- Replace spreadsheet- and ticket-driven renewals with standards-based, automated enrollment and renewal.
- Support web, container, IoT/OT, and enterprise endpoints through 1 CA strategy and the right protocols for each workload.
- Keep CA operations, keys, and audit control aligned with sovereignty and compliance expectations.
- Increase operational consistency by aligning certificate lifecycle management with Red Hat Enterprise Linux identity, host management, and Ansible Automation Platform practices.
- Prepare for cryptographic change by building crypto-agility into the same automation foundation used for routine renewals.
Red Hat’s approach simplifies certificate management by enabling automated, high-frequency renewals without sacrificing enterprise control. We offer both business and technical stakeholders a shared strategy to evolve from today’s certificate risks to a durable, automated future.