- Key algorithms
- RSA 2048 / 3072 / 4096 and ECDSA P-256 / P-384
- Digest
- SHA-256, SHA-384, SHA-512
- Key custody
- YubiHSM 2 over PKCS#11; software keystore for lab and staging
- Enrolment
- ACME, SCEP, EST, REST API and manual CSR upload
- Revocation
- OCSP per RFC 6960; full and delta CRLs per RFC 5280
- Timestamping
- RFC 3161 over HTTP with configurable policy OID
- Signature formats
- PAdES B-B / B-T / B-LT, CAdES detached, raw PKCS#7
- Console access
- OIDC single sign-on for the administration console
- Audit
- Append-only hash-chained event log with signed export
- Deployment
- On-premises or private cloud; Linux hosts or container images
- High availability
- Active-active issuing CAs and responders behind a load balancer
- Interfaces
- REST API, web console and command-line administration