For the complete documentation index, see /llms.txt. Markdown version of this page: /en/products/cyberark/certificate-manager.md.

Machine Identities

Certificate Manager

Certificate Manager keeps track of TLS and machine certificates and automates the work of issuing and renewing them. It was formerly known as Venafi TLS Protect.

What it is

Certificate Manager is a control plane for certificates across an organization. It finds certificates wherever they are deployed, tracks expiry, and automates renewal so services do not break from expired certificates. Policy enforcement keeps certificates aligned with security standards.

Key capabilities

  • Discovers TLS and machine certificates across networks and systems.
  • Issues new certificates from approved certificate authorities.
  • Renews certificates automatically before they expire.
  • Enforces policy on key length, validity period, and issuer.
  • Maintains an inventory and reporting on certificate status.

Who it’s for

Certificate Manager fits organizations that run many services protected by TLS. It helps security and operations teams prevent outages from expired certificates and keep certificate practice consistent.

Read more on Idira (CyberArk)

Questions or inquiry? [email protected] Contact us →