A data security specialist by Swiss Post

Main section

Managed PKI – Setup & Support

On this page, you will see how certificates can be managed through the Managed PKI service. Please make sure which CA you are using and follow the appropriate instructions.

Does your CA look like this?

If you are using the previous CA (prior to August 4, 2022), please follow the instructions below. 

1. Introduction

SwissSign Managed PKI service customers are set up individually on SwissSign infrastructure in order to manage their certificates.

1.1. SwissSign and Managed PKI

2. Managed PKI setup

3. Issuing certificates

4. Interface configuration for partner applications (CMC configuration)

Depending on the order, your SwissSign Managed PKI solution is supplemented with interface standards CMC and RFC 2797 / RFC 5272.

This allows full auto enrolment with our partner products.

To make configuring this interface easier for you, we have prepared various configuration examples in the directory below.

You use:

4.1. NoSpamProxy guide >>
4.2. SeppMail guide >>
4.3. SX-MailCrypt guide >>
4.4. Totemo guide >>

5. Explanation of domain validation

Does your CA look like this?

If you are using the new SwissSign CA (from 4 August 2022), please follow the instructions below. 

1. Introduction

SwissSign Managed PKI service customers are set up individually on SwissSign infrastructure in order to manage their certificates.

1.1. SwissSign and Managed PKI

2. First steps with your Managed PKI

2.1 Onboarding with SwissID
To access your MPKI, your MPKI operators must create an account via SwissID and have your identity verified. It is important that the SwissID account is created with the same operators' email addresses that you provided when ordering your MPKI. 

2.2 MPKI guide (PDF)

2.3 RA Operator Handbook

Once you logged in you can find the latest operator manual under the link "Manual" at the bottom left in the navigation of your MPKI. 

3. Interfaces for the automation of your MPKI

Log in directly to your MPKI

Please note that an identity verifiation is required before the first use of your Managed PKI. 
See 2.1 above Onboarding with SwissID