PKI Proxy offers a secure, self-hosted solution for remote code and document signing through centrally managed cryptographic keys. It supports a variety of key storage devices including HSMs and USB tokens, ensuring the private key remains protected on the server. Clients can access the service using standardized drivers or direct web API calls, enhancing flexibility across platforms and environments.
Key Storage Integration
PKI Proxy supports multiple key storage methods such as hardware security modules (HSMs), PFX certificate files, ECDSA keys, and USB hardware tokens like Yubikey and DigiCert.
Secure Remote Signing
Enables remote applications to sign code and documents without exposing private keys by processing signing requests via the PKI Proxy server, which keeps keys securely on the host system.
Multiple Client Access Methods
Clients can utilize the included PKCS driver, Windows Key Storage Provider (KSP), command line tools, or the Web API to interact with PKI Proxy and perform cryptographic operations remotely.
Robust Security Measures
All communications between clients and the PKI Proxy server are encrypted using SSL/TLS. Private keys never leave their storage locations, and sensitive data is encrypted at rest using DPAPI.
Comprehensive Authentication and Access Control
User authentication supports secret keys, HTTP Basic, and NTLM protocols. Access to individual certificates can be restricted to authorized users, with granular control managed via the PKI Proxy application.
Web API for Programmatic Access
Exposes RESTful endpoints for listing keys and certificates, signing, encrypting, decrypting data, and verifying signatures.
Certificate and User Management
Administrators can centrally manage which certificates are shared, assign user access rights, and configure authentication methods.
Cross-Platform Client Support
The PKCS driver supports Windows, Linux, and macOS clients, facilitating wide compatibility and ease of deployment across heterogeneous IT infrastructures.
Logging and Notification
Supports detailed auditing of operations with configurable log verbosity and optional user notifications for signing events.
Flexible Deployment and Startup Configuration
PKI Proxy can be run as a user-mode background process or a system service and can be configured to start automatically on system startup, suitable for both interactive and unmanned server environments.
Product Compatibility
Review the details below to ensure this product is supported within your environment.
Component Type
Driver
About /n software
/n software, founded over 30 years ago and headquartered in North Carolina, specializes in platform-specific components and libraries that help developers implement secure communications, encryption, network management, and integration with cloud and enterprise systems. Its extensive product portfolio includes IPWorks, SecureBlackbox, BizTalk Adapters, and more, supporting environments such as .NET, Java, Python, C++, and others. /n software components are widely adopted by enterprise developers and trusted in Fortune 500 organizations for building connected desktop, web, and mobile applications.