See below the new features in Certificate Manager for Cryptographic Security Platform 1.5.0.

Bulk certificate automation (ATEAM-19075)

Certificate Manager now provides comprehensive bulk certificate automation, including:

  • Linux and Windows bulk destinations
  • Customer-supplied pre- and post-issuance Ansible playbooks
  • HashiCorp Vault and Key Manager integration
  • Configurable key algorithms
  • Dynamic per-host subject DNs and SANs
  • Shared or per-host certificates
  • Automatic renewal with optional revocation of replaced certificates

Destinations Support Selecting the Key Algorithm and Size (ATEAM-18911)

Ansible destination plugins no longer hardcode RSA 2048. The key algorithm and key size are now configurable, including support for PQ algorithms.

Apache Destinations Support Password Authentication (ATEAM-19187)

The Apache destination plugin now supports password-only authentication without requiring a private key.

CA Gateway source plugin supports a PEM truststore (ATEAM-19191)

The CA Gateway source plugin supports configuring a PEM truststore in addition to the existing support for a PKCS#12 truststore.

Support for multiple certificate filters (ATEAM-19248)

Certificate Manager now supports combining multiple certificate filters when listing certificates in the user interface or generating reports.

Extended custom field limit (ATEAM-19250)

List-type custom fields now support large value sets of up to approximately 80 values.

Public enrollment forms support certificate download (ATEAM-19289)

Certificates enrolled through public enrollment forms can now be downloaded in addition to being copied.

Enrollment forms support logos and header text (ATEAM-19479)

Public enrollment forms now support custom logos and header text, allowing organizations to tailor the appearance of enrollment pages.

Certificate chain validation (ATEAM-19313)

Certificate chains are now validated before being stored in the database or pushed to destinations.

Discovery Scanner uses a supported Java version (ATEAM-19320)

Discovery Scanner now uses a currently supported Java version, replacing the OpenJDK 17 early-access build.

Removal of JasperReports-based report formats (ATEAM-19351)

JasperReports-based Word, PDF, and Excel report formats have been removed. CSV remains the only supported report export format.