TrustRadius: an HG Insights company

Cyberark Certificate Management

Score9.2 out of 10

6 Reviews and Ratings

What is Cyberark Certificate Management?

Venafi Zero Touch PKI is a SaaS-based enterprise PKI solution offered by Venafi, Inc. According to the vendor, it is designed to replace outdated PKIs like Microsoft Windows PKIs and EJBCA. The product aims to provide a hassle-free experience by eliminating the need for dedicated staff, numerous servers, special hardware, and expensive security monitoring. It is targeted at small to large enterprises, including industries such as financial services, healthcare, and retail.

Read more details.

Streamlining Security with Ease

Use Cases and Deployment Scope

We use Venafi Zero Touch PKI to handle our certificates automatically, so we don’t have to worry about them expiring or messing things up. It keeps things secure and running smoothly without much manual work.


Pros

  • It handles our certifications; no manual labor is required.
  • keeps things from breaking by promptly renewing certifications.

Cons

  • The user interface may be simpler to use.
  • There isn't much space to modify things as we would like
  • Sometimes it can be difficult to set up integrations.

Return on Investment

  • The team does less manual labor.
  • Maintains uninterrupted operations
  • It keeps us safe without requiring additional work

Usability

Alternatives Considered

GlobalSign Managed PKI Platform

Other Software Used

Atlassian Jira, Miro

Venafi Is The Best Solution For Private Key and Certificate Management

Use Cases and Deployment Scope

Venafi is used across our entire organization. A few key business problems that Venafi addresses include a very efficient method in securing and protecting certificates and private keys, improving full certificate provisioning by automating the process and including options to schedule installs which prevent certificate related outages, as well as certificate and key discovery options that help ensure accurate inventory.

Pros

  • Venafi includes features that automate the installation of certificates as well as validating the certificates to ensure that they were installed correctly. When used properly this feature will prevent certificate related outages by confirming that a valid certificate is in place and automatically installed prior to its expiration.
  • Venafi includes an option for network discovery, host agents, and an onboard discovery tool that when deployed gives application owners the ability to discover and manage all private keys and certificates in their environment.
  • Venafi helps an organization with its security policy enforcement and provides a method to measure compliance.

Cons

  • The Venafi platform is constantly evolving through its upgrades which occur every quarter to meet client's specific needs. This is an outstanding model however the documentation that follows the upgrades could be more thorough.

Return on Investment

  • An outage is a very devastating event to any large corporation and can cost millions. Venafi's ability to prevent these outages has proven to be a great return on investment for our environment and has helped protect the bottom line.
  • Venafi automates certificate installation with an included feature to schedule the install in advance. This is a great benefit of the tool because it eliminates human error and prevents any forgotten or overlooked certificates to be renewed. After installation Venafi will also validate the certificate to confirm that it has been installed properly. This shows just how thorough this tool really is.
  • Security compliance is of the utmost importance in a large organization for auditing purposes and certificate security policies but at times can prove to be difficult to enforce. Venafi has proven to play a pivotal role in enforcing these policies in our environment.

Venafi is the best choice for complete Digital Certificate Lifecycle Management

Use Cases and Deployment Scope

I have implemented Venafi at 2 previous employers for the entire organization. The first employer had a need to manage the entire Digital Certificate Lifecycle Process due to the explosion in Digital Certificate use cases, costly outages due to certificate expirations and the impact on operations. We were successfully able to automate certificate renewals for F5 Load balancers, Windows IIS 7/8 and Tealeaf devices.

The second employer was replacing a completely home grown system that was outdated and only handled the requests and approval process. We set up a fully integrated Venafi solution with an existing requesting system. We also heavily relied on and used Venafi's REST API for private and public cloud use cases. At the time of departure the other departments of the firm where looking into integrating Venafi into their systems as well.

Pros

  • Digital Certificate Inventory Management and Monitoring
  • Digital Certificate Lifecycle Processes to include ownership and roles and responsibilities
  • Easy automation integration into many common products
  • Certificate Trust Store Management

Cons

  • Exporting of Data to other reporting tools
  • They should create a an OCSP option as Microsoft's implementation is poor
  • Continue to improve their custom adaptor tool

Return on Investment

  • The biggest impact is preventing costly outages due to expired or compromised certificates
  • The second biggest advantage is the savings in operational costs related to the implementation and renewal of certificates
  • The biggest negative is the initial cost and start up of implementing Venafi.