Secure Office Certification Authority

The Secure Office CA is a federal class root certification authority solution for large organisations and public CAs. It is designed for organisations that want to own and operate the technology either to provide in-house services or to provide commercial services to other organisations as a trusted third-party.

  • Federal class root certification authority: multiple independent virtual CAs.
  • Standard or custom certificate attributes and extensions supported.
  • Qualifiable primary certificates and secondary employee/role certificates.
  • Third party LDAP directories and central directory schemas supported
  • Comprehensive accountability auditing.
  • Workflow definitions for large-scale certificate handling.
  • End user self-service for routine procedures.
  • Certification and smart cards are also available as an outsourced service.

The Secure Office CA can act as the root authority in an organisation of any size, it can generate any number of subordinate CA instances that each support an independent organisation, or it can be subordinated to the root CA in any existing PKI. A truly scalable system, Secure Office easily supports massive PKI demands, extensive auditable histories and large-scale certificate storage.

Far from simply issuing certificates, Secure Office provides management on a scale commensurate with national or multi-national certification schemes, maintaining a comprehensive, auditable history of all information concerning cards, users, certificates and administrative activities. User / certificate / card information may be entered manually or can be imported from any existing cards, certificates, central directories or public catalogs.

IT support costs are reduced by workflow management definitions for handling large scale certificate operations and by user self service for routine procedures such as updating certificate validity periods and user data.

Secure Office supports both distributed Certificate Revocation Lists and Online Certificate Status Protocol for control of revocation information. An OCSP responder is included in the system.

Administration is through standard web browsers and secured by smart card role-based access control. Secure Office supports central directory network strategies and certificate publishing over LDAP, LDAPS, FTP, HTTP and HTTPS.