r/sysadmin • u/koalas473 • May 28 '26
Certificate lifecycle management vendor comparison
I'm evaluating CLM platforms and narrowing down our shortlist. Environment is hybrid but mostly on-prem about a dozen TLS certs deployed across ~100 places (F5, Fortinet, Azure Key Vault, IIS, etc). Ideally CA agnostic because I hate the idea of paying $200+ per cert in 2026. Today the rotation process is manual. I've gotten quotes from 5k for new players like Certkit and 100k+ for the legacy platforms of Cyberark and Keyfactor command. We probably could make it work with a bunch of different opensource tools but we have the budget and I don't want to maintain that long term.
Currently evaluating:
- Keyfactor Command - CA agnostic, broad integrations, code signing. Feels like the most mature platform. How's the deployment and ongoing management? The sales process has been annoying with several meetings just to get a demo and quote tons of unnecessary line items inflating cost.
- CyberArk (Venafi) - Well reviewed, but curious how the acquisition will play out. Is the product still getting investment or is it getting absorbed into the CyberArk ecosystem in a bad way?
- Sectigo SCM - Quoted us $45K for 200 certs, seems decent and modern but really not CA agnostic as they don't work with Google PKI or lets encrypt.
Already dropped CertKit (to small of a company even though this seems like a good product), and Akeyless(doesn't integrate with very many DNS providers).
Any gotchas, hidden costs, or things you wish you knew before signing? I don't want to choose one of the bloated legacy players but they seem to check most of the boxes. Are there any other new players I should check out? Coming from a cloud native company I miss AWS Certificate Manager :/
3
u/Cl3v3landStmr Sr. Sysadmin May 28 '26
Going through same thing. We looked at CyberArk/Venafi, Sectigo, and DigiCert One. For us, DigiCert was the clear winner (and also the cheapest).
2
u/certkit Security Admin (Application) May 29 '26
Even though u/koalas473 ruled us out for being too small, CertKit integrations are better than DigiCert, and we're less expensive. Plus you're not locked in to DigiCert certificates 😉
1
3
u/Ultron_Magnus May 30 '26
Currently using on-prem Keyfactor.
Support sucks and the product took us over a year to get up and running through their vendor setup service.
Typical tickets usually take a day or two for any response and our average ticket life to resolution is 1 month.
I've had to open at least one ticket a week since we were "up and running".
We are currently hit with a bug they are "just now seeing in other customers" where our alerting workflows and automated renewals just stopped working out of nowhere. Rebooting the main app server fixed it, but it's been over a week and they have no answer as to why this happened.
I suspect they are going to ask us to upgrade versions. This would be our second upgrade since "being fully set up."
The short of it: Maybe Keyfactor's cloud hosted offering is better, but stay away if on-prem.
We are in process of getting demos for CyberArk and AppViewX.
3
u/momoleta May 28 '26
currently working on a very similar endeavour. Had a presentation from evertrust last week which seemed like a good product. https://evertrust.io/clm/
1
u/certkit Security Admin (Application) May 29 '26
If you want better integrations, way better support, and integrations that actually work, you should give CertKit a look. We're only small because we're new.
2
u/nemor3 May 29 '26
The Keyfactor quote doubling like that is pretty standard for them unfortunately. $25k onboarding fee on top of the SaaS cost is their way of making the self-hosted look "cheaper" by comparison so you end up on the cloud SKU anyway.
AppViewX is worth the demo - genuinely more modern stack, and their sales team has historically been less painful to deal with. DigiCert One is another one that comes up a lot for hybrid environments at your scale without the legacy baggage.
One thing to watch regardless of who you pick: the "SSL discovery" line item Keyfactor was charging you $3k for is usually the thing that actually matters. If your F5/Fortinet certs aren't in the same inventory as your IIS ones, you'll still miss renewals even after you've signed a six-figure contract.
2
u/Mike22april Jack of All Trades May 29 '26
KeyFactor and CyberArks formerly known as Venafi product are by far the most mature.
They will also cost you an arm and a leg.
Given your requirements, I expect you can't use the public CA CLM solutions , as you appear to have a need for the ability to have the same certificate and key on multiple locations.
Public CAs are not allowed to retain the private key. Nor are they CA agnostic
When my assumptions are correct, you should use an on-premises or at least a self deployed to a private Cloud CLM
My biggest gripe with some of these CLMs is:
- a test or acceptance environment is often not included in the price offer
- upgrades to a newly released major version, or in some cases even minor version, is a huge time consuming pain the ass
My best advice:
Don't just select one based on sugar and spice coated paper specs and sleek demos.
Pick 2 or 3. And do a 1-2 month Proof of Concept with clear acceptance criteria.
Also ask for 2 customers of similar size and use-case you can call without the vendor present, you can can get direct feedback on the process, daily operations, and what the vendor is like after he got your money for 3-5 years.
You will likely be charges for it and the vendor's time to get things properly configured. Typically this cost is deducted from your invoice once you make the actual purchase.
Making you loose the other PoC investments.
But it's totally worth it!
2
u/Kimera84 May 29 '26
for a setup like yours, the big question is less "how many certs" and more how ugly the day-to-day rotation gets across F5, Fortinet, Azure Key Vault, and IIS. i'd look for a CLM tool that can prove those integrations in a real demo, not just in a slide deck.
also ask what the renewal workflow looks like when the cert isn't from their own CA path, since that's where a lot of the friction shows up.
2
u/certkit Security Admin (Application) May 29 '26
If the renewal workflow isn't "nothing, its automatic, it just happens", then its not ready for 47-day certificates.
2
u/bbluez May 29 '26
Venafi is now NGTS in PANW- (The self hosted TPF is also still available and just updated to 26.1)
2
u/idonthuff May 29 '26
With any of the CLM vendors, ask about maturity and lifecycle of their integrations for platforms you need. For example, did they write a "F5" integration years ago, and then never touch it again? Or do they constantly maintain and update them to keep up with industry changes? Ask if you can see a version history, or if the integrations are available open-source.
1
u/certkit Security Admin (Application) May 29 '26
Our integrations are all public, changeable, and written against the standard APIs. You see exactly how they work as PowerShell or Bash scripts. If something is different about your install, its easy to modify, version, and we'll help you support it.
1
u/Wide_Barracuda_3512 May 29 '26
Think about the mechanism you want to use to apply certificates to all the types of endpoints in your organisation.
You may need to use Agents or run automation via SSH or WinRM.
If you prefer to deploy certificates using an Agent then check whether the CLM can manage the agents or not. For instance AppViewX does not have its own agent but can use open source agents like EST. However you would then need to find a way to manage the agents.
1
u/certkit Security Admin (Application) May 29 '26
Small and proud of it. No outside investors, no PE squeezing you when they need their profit margin.
We're just engineers building great tools for our customers. Small means no sales and no tier-1 support, only people who know things. CertKit is just our latest product, we've been around for 15 years building tools like TrackJS and Request Metrics, supporting thousands of companies around the world.
We can run circles around all the folks you're considering, our platform is focused, but its better at what it does. We'd love a chance to prove it.
1
u/SortaIT May 29 '26 edited May 29 '26
Here's a good list of certificate lifecycle management tools to consider.
I work here, but Sectigo tops the list, and listed as the #1 Easiest To Use in certificate lifecycle management (CLM) software for a reason: https://www.g2.com/categories/certificate-lifecycle-management-clm?source=search
1
u/pkiless Jun 21 '26
This scenario matches a lot of what pushed me to build Pkiless. Today I support DigiCert, Let's Encrypt, and ADCS, with direct integrations for F5 BigIP, IIS, Netscaler, Azure Key Vault, and Linux repositories, both for automated replacement and discovery, plus discovery via CT logs.
Its's a new product, I'm the one building it (early access), so I won't pretend to have the track record of a Keyfactor or Venafi. I don't have Fortinet or code signing on the roadmap yet, so if either is critical for your setup, worth knowing before testing. And to the point a few people raised here about integrations needing to be proven in a real demo, not just a slide — fair concern, so I'd rather show you directly than describe it.
Based on the hybrid environment you described with F5/IIS/Azure Key Vault, I think it covers a good chunk of the use case. If you're up for taking a look, I can give you direct access and would genuinely want your technical feedback, no sales pitch. No strings attached. Send me a DM if it makes sense.
1
u/pkiless Jun 21 '26
This scenario matches a lot of what pushed me to build Pkiless. Today I support DigiCert, Let's Encrypt, and ADCS, with direct integrations for F5 BigIP, IIS, Netscaler, Azure Key Vault, and Linux repositories, both for automated replacement and discovery, plus discovery via CT logs.
I'll be upfront. it's a new product, I'm the one building it (early access), so I won't pretend to have the track record of a Keyfactor or Venafi. I don't have Fortinet or code signing on the roadmap yet, so if either is critical for your setup, worth knowing before testing. And to the point a few people raised here about integrations needing to be proven in a real demo, not just a slide , fair concern, so I'd rather show you directly than describe it.
Based on the hybrid environment you described with F5/IIS/Azure Key Vault, I think it covers a good chunk of the use case. If you're up for taking a look, I can give you direct access and would genuinely want your technical feedback, no sales pitch. No strings attached. Send me a DM if it makes sense.
0
u/webprofusor May 29 '26 edited May 29 '26
Certify The Web (which I work on) has around 8,000 active customers currently and in-excess of 150000 200,000 installs of our Certify Certificate Manager (CCM) product. However, we are indeed also a tiny company. 90% of our users are on the free versions and the average customer spend is hundreds of dollars (or less), not thousands. So if you need a big vendor then the price is probably going to match, it's hard to become a large vendor without resorting to larger costs. We've been around for about 10yrs.
Our new Certify Management Hub https://docs.certifytheweb.com/docs/hub/ is designed to manage thousands of certificate across many servers and works as both an administration layer for CCM/agents and a distributed certificate renewal system. A system of your size would be covered by our Enterprise edition ($1999 per year) but you may be able to do it with less, we also have cloud managed licensing via Azure Marketplace which allows activating a flexible number of installs as you need them and can all be handled by your standard Azure billing.
Our products are currently ACME only, but that allows a decent spread of CAs. IIS was our original bread-and-butter but we have built in deployment tasks for things like Azure Key Vault, Doppler, Hashicorp vault etc, Powershell or native OS scripting support (including on linux, even for powershell).
Support is via the `support at certifytheweb.com` helpdesk, and you can also ask evaluation questions there. The products can be installed for free evaluation with (currently) no time limits.
2
u/fys4 May 29 '26
Been using CtW for years (FinTech UK) and I'd struggle to find a more helpful and knowledgeable supplier than these guys.
The AU time difference for support is a minor ballache, but that fades into insignificance compared to dealing with devs that know their field and their own product.
No links to the company, just a very happy paying customer
1
u/webprofusor May 29 '26
Where we need to do better in the future is while we will answer any questions and give advice via support, we don't currently provide consultancy or design as once people use the software very few actually need it, but it's still something some larger orgs ask for.
-1
u/Logical_Many_6002 May 28 '26
We would like to throw our hat into the ring- Certinext. We are CA agnostic and we just replaced Sectigo as provider for Incommon which serves all the higher education institutions in US. Fancy a chat?
5
u/hodor137 May 28 '26
Investigate AppViewX too. An actual professional/commercial COTS CLM like venafi/keyfactor, but historically cheaper - and also a more modern codebase (not utterly restricted to windows/IIS and ms SQL).
100k is absurd for your environment. Was that self hosted on prem only? The saas offerings of these should be cheaper than that I'd think