A complete PKI, ready to test.
Build certificate authorities, issue certificates and check enrollment end to end over SCEP, EST, ACME, CMP and CES — without installing and maintaining a PKI of your own. Plus cryptographic utilities, expiry monitoring, an API for CI and teamwork.
- Multi-level CA hierarchies
- Classic and post-quantum algorithms
- Traffic captures for Wireshark
Who it is for
QA teams
Reproduce real enrollment and revocation scenarios, with valid, expired or revoked certificates on demand, and see exactly what went over the wire.
Developers
Integrate applications and devices with a real PKI: protocol endpoints, public OCSP and CRL, plus an API for everything you do in the web UI.
Testing and integration
Validate switches, routers, MDM, ACME or Windows clients before production, and compare their behaviour with other SCEP, EST or CMP servers.
The whole certificate life cycle, in one place
From the Root CA to the certificate on the device: hierarchies, profiles, issuance, renewal, revocation and audit — configurable down to each extension.
Certificate authorities
Root CA and Sub CAs as a tree, over several levels; import of existing CAs, RA certificates, renewal, revocation and a hierarchy map with each CA's services.
Profiles and templates
Ready-made templates for Root, Intermediate, End Entity, OCSP Responder and RA; key usage, EKU, SAN, certificate policies, validity window and CSR key policy.
Certificates and CSRs
Issue with a generated key or from a CSR, generate and import requests, download as PEM, DER or PKCS#12 with the full chain.
Modern algorithms
RSA, ECDSA and EdDSA (Ed25519, Ed448), plus the post-quantum ML-DSA and SLH-DSA — so you can test the migration early.
Real-time revocation
Public OCSP responders and CRL distribution points with automatic refresh; their addresses go into issued certificates automatically.
Full audit
Every issuance, revocation, configuration change, key export or rejected enrollment, with who did it and why.
Real endpoints for every protocol
Start an endpoint in seconds and point the device, client or script under test at it.
Switches, routers, printers and MDM: static or one-time challenge, manual approval, separate RA, renewal, CA rollover.
Enrollment over HTTPS: enroll, reenroll and server-side key generation, with password or client-certificate authentication.
Automatic server certificates with certbot, acme.sh or Caddy: http-01, dns-01, External Account Binding.
The full life cycle over CMPv2 — enrollment, key update, revocation — protected by a shared secret or a certificate.
Certificates for Windows computers through the enrollment policy and enrollment services, renewal included.
Revocation checking by clients, with dedicated responders and automatically published lists.
Troubleshooting tools other PKIs do not have
SCEP, EST, ACME and CMP clients run from the platform, against your endpoints or external servers.
Record an endpoint's, client's or proxy's exchanges and open them in Wireshark; the Algorithms window shows signatures, keys and ciphers.
Route a device's traffic to another SCEP, EST or CMP server through the platform, so you can capture and analyse it.
Make the answers look like another server's and find the difference a device stalls on.
The everyday cryptographic toolkit
Everything you usually reach for openssl in a terminal for, organised and explained — right in the browser.
Stored key pairs, exported as OpenSSH, PuTTY or PEM.
Certificates, CSRs, CRLs, keys, PKCS#7 and PKCS#12 in plain text, from a file or a TLS server.
Between PEM, DER, PKCS#7 and PKCS#12; add or remove a key's password.
Two certificates, CSRs, keys or CRLs, field by field.
Chain, expiry, name and revocation, plus a bulk check.
Check that a key belongs to the certificate before installing it.
Detached, CMS and PDF (PAdES) signatures, post-quantum included.
SHA-2, SHA-3 and more, for files and text.
Argon2, scrypt, PBKDF2, HKDF, and how well an encrypted key is protected.
The raw structure of any cryptographic object.
Values, tokens and strong passwords.
Know before anything expires
The platform watches your servers' and PKIs' certificates and warns you early, by email.
- Server certificates on any port, STARTTLS included (SMTP, IMAP, POP3 and more)
- The authorities of your PKIs and, on request, the certificates they issued
- Revocation lists (CRLs) about to expire
- Tiered alerts, including on the expiry day, and connection errors
Everything you do in the web UI, from CI too
A fully documented REST API, for pipelines that build their own test PKI, issue certificates and check the result.
- More than 80 operations: PKIs, certificates, endpoints, DNS, monitoring, captures, Let's Encrypt and TLS tests
- OpenAPI 3.1 specification and an automatically generated reference
- An in-platform API console showing the exact response and the equivalent curl request
- Personal tokens, read-only when needed, with usage statistics and a warning before expiry
- Single-use test PKIs, deleted at the end with all their certificates
curl -X POST "https://pkiplayground.com/api/v1/pki/1/certificates" \
-H "Authorization: Bearer $SECAAS_TOKEN" \
-H "Content-Type: application/json" \
-d "$(jq -n --rawfile csr device.csr \
'{csr: $csr, profile_id: 3, issuer_ca_id: 2}')"
# 201 Created
{
"id": 345,
"subject": "CN=device-01",
"status": "valid",
"pem": "-----BEGIN CERTIFICATE-----…"
}
Work together, safely
Every colleague has their own account in the same organisation, with rights that fit their role.
Team roles
Owner, Administrator, Member and Read only — each sees and changes exactly what they should.
Two-step sign-in
A 6-digit code from the phone app at every sign-in, with recovery codes.
Invitations and notifications
Invite colleagues by email and choose who receives the expiry alerts.
Isolated data
Private keys and secrets are encrypted; every organisation sees only its own data.
Related services for your tests
Hosted zones with A, MX, TXT, CAA and other records, DNSSEC signing and queries to any server. ACME dns-01 validation works automatically.
Free public certificates over HTTP-01 or DNS-01: issuance, download and renewal.
What a server negotiates: versions, ciphers, certificate, chain and OCSP stapling, with a Wireshark capture and a PDF report.
The platform is built for development, QA and the lab. Use it to build, try and learn; the certificates and keys here are not meant for production systems.
Start your first test PKI in minutes
Create a certificate authority, start a SCEP or ACME endpoint and point your first device at it.
Have a question?
Email us and we will get back to you as soon as we can.
contact@secaas.tech