TigerTrust vs Entrust

Modern multi-CA management around your Entrust certs.

Entrust is one of the most established names in enterprise PKI, and Entrust Certificate Services is a solid management portal for Entrust-issued certificates. TigerTrust adds the CLM layer above it — CA-agnostic, cloud-native, and Kubernetes-native.

Why teams switch

Keep Entrust as your CA. Modernise the platform.

Entrust has decades of PKI credibility and a strong CA business. Their management portal is capable but scoped to Entrust — most enterprises need one CLM across every issuer.

Full multi-CA freedom
Entrust plus DigiCert, Sectigo, GlobalSign, Let's Encrypt, private CAs, ADCS, Vault — orchestrated through one policy plane.
Cloud-native SaaS delivery
Modern SaaS architecture, cross-cloud discovery (AWS, Azure, GCP), Kubernetes-native — plus on-prem for regulated estates.
Platform + cert costs separated
One platform fee. Entrust certs at your negotiated rate. Free issuers where policy allows — no forced upsell.
Modern developer surface
REST, GraphQL, Terraform, cert-manager, and a first-class CLI. Built for the DevOps workflows Entrust was never architected around.
The move off

What changes when the platform is CA-agnostic.

Without Entrust
  • Management portal scoped primarily to Entrust-issued certificates
  • Limited native support for non-Entrust CAs
  • Kubernetes and DevOps integrations feel bolted on
  • On-premise-heavy deployment model with mandatory services attach
  • Cost tied to Entrust certificate consumption
With TigerTrust
  • Every certificate — Entrust or not — in one platform
  • True multi-CA orchestration with policy-driven routing
  • First-class Kubernetes, Terraform, and GitOps workflows
  • Cloud SaaS or air-gapped on-prem, self-service where possible
  • Platform pricing separate from what you spend at any CA

Capability comparison, head to head.

Entrust is a top-tier public CA. Certificate Services is its management portal, not a general-purpose CLM. Here is where the two overlap and where the delivery differs.

CapabilityTigerTrustEntrust Certificate Services
Entrust CA issuance & renewal
Entrust is authoritative for Entrust-issued certs
Multi-CA orchestration
Certificate discovery (network, cloud, K8s)
Kubernetes cert-manager integration
ACME protocol / Let's Encrypt
Cloud-native SaaS delivery
GraphQL API
Terraform provider
HSM integration & FIPS 140-2 support
Entrust has particularly strong HSM heritage via nShield
Public CA trust anchors
Entrust operates its own WebTrust-audited public trust anchors

Keep Entrust. Add TigerTrust.

You do not have to leave Entrust to modernise the platform. Most teams keep Entrust as a preferred CA and add TigerTrust as the CLM.

01

Connect Entrust CS

Add Entrust as an issuer in TigerTrust using your existing Certificate Services API credentials. Current inventory imports automatically.

02

Add other CAs

Bring in DigiCert, Sectigo, private CAs, ADCS, Let's Encrypt — whatever else is in the estate. Policy routes each request to the right CA.

03

Turn on discovery

Point discovery at your clouds, Kubernetes clusters, and network ranges. Every certificate appears in one inventory, regardless of issuer.

04

Automate lifecycle

Enable ACME endpoints, cert-manager issuers, Terraform, and webhook renewals. Entrust keeps issuing; TigerTrust handles the rest.

Frequently asked questions

Do we have to leave Entrust to use TigerTrust?

No. Entrust stays as an issuer for the certificates you rely on them for — high-assurance TLS, code signing, EV, and workloads with strict trust requirements. TigerTrust sits above Certificate Services as the CLM plane.

Does TigerTrust support Entrust nShield HSMs?

Yes. TigerTrust integrates with Entrust nShield HSMs (and other PKCS#11-compatible HSMs) for key storage. Your existing HSM investment remains authoritative.

How does the CS integration work?

TigerTrust uses the Entrust Certificate Services API to enroll, retrieve, and revoke Entrust-issued certificates. Your CS account structure, validation model, and contract stay intact.

What about our on-premise Entrust PKI deployment?

TigerTrust can be deployed on-premise, including air-gapped environments, and can front an on-prem Entrust PKI as one of the upstream issuers. You do not have to choose between cloud and on-prem.

How is pricing structured?

Platform pricing is separate from Entrust certificate costs. You keep your Entrust contract; TigerTrust adds a platform fee for the CLM layer. Ask us for a side-by-side against your current line items.

Case study
Regulated · Financial services

Kept Entrust and nShield authoritative, modernised the CLM plane above them.

Entrust and our nShield estate were non-negotiable. We wanted a modern CLM plane above them — one that treats DevOps like a first-class citizen.
Head of Cryptography Engineering
7 wk
Time to unified inventory
620K
Certificates across CS + private roots
3x
Faster renewals on regulated workloads
Integrations

Entrust plus every other CA under one policy plane.

Keep Entrust for high-assurance issuance. Add the CAs and DevOps integrations Entrust Certificate Services does not natively orchestrate.

Entrust Certificate Services
CA
Entrust nShield HSM
HSM
Let's Encrypt
CA
DigiCert
CA
Microsoft ADCS
CA
HashiCorp Vault
CA
Kubernetes cert-manager
DevOps
HashiCorp Terraform
IaC
ServiceNow
ITSM

Modernise the platform without leaving your CA.