EZCA - Azure + Intune Cloud PKI

EZCA allows you to run and scale a private CA service without the upfront investment and ongoing maintenance costs of operating a private CA or CA hierarchy.

EZCA allows you to run and scale your own highly available private CA service without the upfront investment and ongoing maintenance costs of operating a private CA or private CA hierarchy. Whether you are creating a new private PKI hierarchy or chaining up to an existing one, EZCA will help you create it by following the latest industry standards.

Automated Multi-Cloud Certificate Lifecycle

EZCA integrates with key management systems (Azure Key Vault, AWS KMS), Windows, and Linux to empower you to automatically manage and rotate all certificates across multi-cloud and hybrid deployments.

WebTrust Level Security

Offload time consuming tasks such as HSM provisioning, PKI patching, CRL distribution, disaster recovery, and more to the cloud. EZCA allows your team to quickly deploy a highly available HSM backed PKI deployment in a few clicks. Leaving the PKI management to our world class PKI experts and freeing up your team to work on other pressing security tasks.

Secure By Default

While other legacy PKI solutions are hard to set up increasing the probability of a misconfiguration that can cause an outage or even worse; expose your company. EZCA was designed and tested by PKI experts across the world. Making it easy for anyone to set up a world class HSM backed PKI in minutes.

Certificate Authorities (CAs) for All Your PKI Needs

EZCA supports a variety of CA types to meet your organization’s PKI needs:

  • Root CA - Create a root of trust for your PKI deployment.
  • Issuing CA - Create an issuing/subordinate CA to issue certificates for your organization.
  • SCEP CA - Create a SCEP CA to issue certificates to devices via the SCEP protocol.
  • GlobalSign MSSL CA - Create a public GlobalSign MSSL CA to issue certificates for your organization using GlobalSign’s Managed SSL service.
  • Azure Firewall TLS Inspection - Create a CA certificate to inspect TLS traffic using Azure Firewall.

EZCA Guides


Learn About Certificate Authorities (CAs) and Managing Private Key Infrastructures (PKI)

Learn how to design and manage your certificate authorities and private key infrastructure through a set of comprehensive guides.

How-To Get Started with EZCA Cloud PKI

This guide will take you through the necessary steps to set up EZCA on your tenant. Modernizing your PKI and get full SSL visibility with EZCA.

How-To: Create a Root CA in Azure

A Root CA is needed to be the root of trust for your PKI Deployment. In this page we will guide you on how you can create your own Root CA either using EZCA or creating your own offline CA.

How-To: Create a Subordinate/Issuing SSL CA in Azure

In this page we will guide you on how you can create your own Issuing SSL CA and chain it up to a Root CA (EZCA Root or Offline Root).

How-To: Create SCEP PKI in Azure Using EZCA

This page will walk you through how to create an Azure based SCEP CA to issue SSL Certificates for your Intune managed devices.

How-To: Automate GlobalSign MSSL Certificate Lifecycle for Free

In this page we will show you how to connect to GlobalSign to issue and automate public SSL certificate lifecycle using the EZCA and all the integrations it offers.

How to Issue Certificates for Azure Firewall TLS Inspection

Azure Firewall requires a CA certificate to inspect TLS traffic and secure the connection between the client and the firewall. This guide will take you through the necessary steps to automatically issue TLS certificates for Azure Firewall.

How To: Manage Your Certificates in EZCA

This section will guide you through managing your EZCA certificates including renewing, revoking, and monitoring certificate status.

EZCA Frequently Asked Questions

Find answers to the most frequently asked questions about Keytos EZCA, the leading cloud-native PKI (Certificate Authority) built for Azure and Microsoft Cloud environments.

Reference: EZCA Swagger Documentation

EZCA Swagger Documentation for API Reference

Reference: EZCA Pricing Breakdown

EZCA Pricing Breakdown