Step CA Pro is an enterprise certificate authority solution that uses hardware-based device attestation to prevent phishing attacks. Built on the ACME Device Attestation protocol co-developed with Google, it leverages TPM or Secure Enclave to verify device identity before granting access to resources. The solution offers on-premises deployment with cloud management, HSM integration, high availability, and supports multiple protocols including ACME and SCEP. It serves as a drop-in replacement for the open-source step-ca project with added enterprise features like FIPS compliance, advanced observability, and centralized management across distributed CAs.
Table of contents
The new security perimeterBuilt on a foundation of open sourceEnterprise-ready by designIt’s time to call the elephant outSort: