A test environment for QA, development and testing teams

A complete PKI, ready to test.

Build certificate authorities, issue certificates and check enrollment end to end over SCEP, EST, ACME, CMP and CES — without installing and maintaining a PKI of your own. Plus cryptographic utilities, expiry monitoring, an API for CI and teamwork.

  • Multi-level CA hierarchies
  • Classic and post-quantum algorithms
  • Traffic captures for Wireshark

Who it is for

QA teams

Reproduce real enrollment and revocation scenarios, with valid, expired or revoked certificates on demand, and see exactly what went over the wire.

Developers

Integrate applications and devices with a real PKI: protocol endpoints, public OCSP and CRL, plus an API for everything you do in the web UI.

Testing and integration

Validate switches, routers, MDM, ACME or Windows clients before production, and compare their behaviour with other SCEP, EST or CMP servers.

PKI infrastructure

The whole certificate life cycle, in one place

From the Root CA to the certificate on the device: hierarchies, profiles, issuance, renewal, revocation and audit — configurable down to each extension.

Certificate authorities

Root CA and Sub CAs as a tree, over several levels; import of existing CAs, RA certificates, renewal, revocation and a hierarchy map with each CA's services.

Profiles and templates

Ready-made templates for Root, Intermediate, End Entity, OCSP Responder and RA; key usage, EKU, SAN, certificate policies, validity window and CSR key policy.

Certificates and CSRs

Issue with a generated key or from a CSR, generate and import requests, download as PEM, DER or PKCS#12 with the full chain.

Modern algorithms

RSA, ECDSA and EdDSA (Ed25519, Ed448), plus the post-quantum ML-DSA and SLH-DSA — so you can test the migration early.

Real-time revocation

Public OCSP responders and CRL distribution points with automatic refresh; their addresses go into issued certificates automatically.

Full audit

Every issuance, revocation, configuration change, key export or rejected enrollment, with who did it and why.

Enrollment protocols

Real endpoints for every protocol

Start an endpoint in seconds and point the device, client or script under test at it.

SCEP RFC 8894

Switches, routers, printers and MDM: static or one-time challenge, manual approval, separate RA, renewal, CA rollover.

EST RFC 7030

Enrollment over HTTPS: enroll, reenroll and server-side key generation, with password or client-certificate authentication.

ACME RFC 8555

Automatic server certificates with certbot, acme.sh or Caddy: http-01, dns-01, External Account Binding.

CMP RFC 9810

The full life cycle over CMPv2 — enrollment, key update, revocation — protected by a shared secret or a certificate.

CES / CEP MS-WSTEP

Certificates for Windows computers through the enrollment policy and enrollment services, renewal included.

OCSP · CRL RFC 6960 · 5280

Revocation checking by clients, with dedicated responders and automatically published lists.

Troubleshooting tools other PKIs do not have

Client consoles

SCEP, EST, ACME and CMP clients run from the platform, against your endpoints or external servers.

Traffic capture (PCAP)

Record an endpoint's, client's or proxy's exchanges and open them in Wireshark; the Algorithms window shows signatures, keys and ciphers.

Proxy to external servers

Route a device's traffic to another SCEP, EST or CMP server through the platform, so you can capture and analyse it.

Interoperability tests

Make the answers look like another server's and find the difference a device stalls on.

Utilities

The everyday cryptographic toolkit

Everything you usually reach for openssl in a terminal for, organised and explained — right in the browser.

Key generator

Stored key pairs, exported as OpenSSH, PuTTY or PEM.

Decoder

Certificates, CSRs, CRLs, keys, PKCS#7 and PKCS#12 in plain text, from a file or a TLS server.

Conversions

Between PEM, DER, PKCS#7 and PKCS#12; add or remove a key's password.

Compare

Two certificates, CSRs, keys or CRLs, field by field.

Trust validation

Chain, expiry, name and revocation, plus a bulk check.

Certificate / key match

Check that a key belongs to the certificate before installing it.

Digital signatures

Detached, CMS and PDF (PAdES) signatures, post-quantum included.

Hash and HMAC

SHA-2, SHA-3 and more, for files and text.

KDF

Argon2, scrypt, PBKDF2, HKDF, and how well an encrypted key is protected.

ASN.1 analyzer

The raw structure of any cryptographic object.

Cryptographic random

Values, tokens and strong passwords.

Domain and PKI monitoring

Know before anything expires

The platform watches your servers' and PKIs' certificates and warns you early, by email.

  • Server certificates on any port, STARTTLS included (SMTP, IMAP, POP3 and more)
  • The authorities of your PKIs and, on request, the certificates they issued
  • Revocation lists (CRLs) about to expire
  • Tiered alerts, including on the expiry day, and connection errors
API

Everything you do in the web UI, from CI too

A fully documented REST API, for pipelines that build their own test PKI, issue certificates and check the result.

  • More than 80 operations: PKIs, certificates, endpoints, DNS, monitoring, captures, Let's Encrypt and TLS tests
  • OpenAPI 3.1 specification and an automatically generated reference
  • An in-platform API console showing the exact response and the equivalent curl request
  • Personal tokens, read-only when needed, with usage statistics and a warning before expiry
  • Single-use test PKIs, deleted at the end with all their certificates
Issuing a certificate from a CSR
curl -X POST "https://pkiplayground.com/api/v1/pki/1/certificates" \
  -H "Authorization: Bearer $SECAAS_TOKEN" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --rawfile csr device.csr \
        '{csr: $csr, profile_id: 3, issuer_ca_id: 2}')"

# 201 Created
{
  "id": 345,
  "subject": "CN=device-01",
  "status": "valid",
  "pem": "-----BEGIN CERTIFICATE-----…"
}
Team and security

Work together, safely

Every colleague has their own account in the same organisation, with rights that fit their role.

Team roles

Owner, Administrator, Member and Read only — each sees and changes exactly what they should.

Two-step sign-in

A 6-digit code from the phone app at every sign-in, with recovery codes.

Invitations and notifications

Invite colleagues by email and choose who receives the expiry alerts.

Isolated data

Private keys and secrets are encrypted; every organisation sees only its own data.

Also included

Related services for your tests

DNS server

Hosted zones with A, MX, TXT, CAA and other records, DNSSEC signing and queries to any server. ACME dns-01 validation works automatically.

Certbot · Let's Encrypt

Free public certificates over HTTP-01 or DNS-01: issuance, download and renewal.

TLS/SSL testing

What a server negotiates: versions, ciphers, certificate, chain and OCSP stapling, with a Wireshark capture and a PDF report.

A test environment, not a production one

The platform is built for development, QA and the lab. Use it to build, try and learn; the certificates and keys here are not meant for production systems.

Start your first test PKI in minutes

Create a certificate authority, start a SCEP or ACME endpoint and point your first device at it.

Contact

Have a question?

Email us and we will get back to you as soon as we can.

contact@secaas.tech