Solutions · PKI Modernization

Retire the legacy CA without a big-bang migration.

Microsoft ADCS, EJBCA on a VM in the corner, three cloud CAs, and something called "the old PKI" that nobody remembers standing up. TigerTrust brings them under one modern control plane — then lets you decommission on your timeline.

The problem

Legacy PKI is the tax you pay on every project.

Manual issuance, weak algorithms, Windows Server 2012 servers nobody wants to touch, and a root ceremony scheduled for "whenever the auditor asks." Every modernisation programme stalls because ripping and replacing feels catastrophic.

Without a modernisation plan
  • ADCS servers running unsupported Windows versions
  • Root ceremonies overdue by years — nobody wants to touch them
  • Weak crypto (SHA-1, RSA-1024) still issuing to production
  • Every cert request routed through a helpdesk queue
  • PQC transition impossible without a modern crypto-agile stack
With TigerTrust PKI modernisation
  • Discovery of every legacy CA — issued, imported, or shadow
  • Coexistence layer bridges ADCS / EJBCA / Vault into one plane
  • Migrate workflows gradually with parallel-run validation
  • Crypto-agile issuance replaces weak algorithms on renewal
  • PQC-ready roots so the next transition is a schedule item, not a project
Discover

Map the entire legacy estate

Passive and active discovery finds every certificate and every CA. See the sprawl clearly — ADCS forests, EJBCA installations, Vault mounts, DigiCert accounts — before deciding what to keep.

How it works
  • ADCS, EJBCA, Vault, cloud-CA discovery
  • Issuer graph with trust-chain visualization
  • Ownership and last-issuance timestamps
  • Risk scoring per CA
Legacy PKI infrastructure discovery dashboard
Coexist

Bridge legacy CAs into the modern plane

Keep ADCS and EJBCA running while TigerTrust proxies requests, unifies logs, and enforces policy centrally. No forklift, no downtime, no revalidation.

How it works
  • ADCS auto-enrolment proxy
  • EJBCA EST / SCEP frontend
  • HashiCorp Vault backend integration
  • Central policy applied across all bridged issuers
Modern PKI plane bridging to legacy infrastructure
Migrate

Move workflows gradually, prove each step

Shift issuance from legacy to modern one workflow at a time. Parallel-run validation catches regressions before they matter. When you're ready, the legacy CA turns off — not before.

How it works
  • Parallel-run validation
  • Per-workflow cutover
  • Rollback to legacy any time
  • CMDB and inventory tracks the transition
Gradual PKI migration workflow
Modernise

Crypto-agile, cloud-native, PQC-ready

Once bridged, you get everything modern PKI needs: short-lived certs, HSM-backed roots, algorithm agility, and a clean path to the NIST post-quantum suites.

How it works
  • HSM-backed roots (Thales, Entrust, CloudHSM)
  • Short-lived certs with automated rotation
  • CNSA 2.0 and PQC (ML-KEM, ML-DSA) ready
  • Cloud-native deployment with Kubernetes
Modern cryptographic infrastructure with post-quantum readiness
The modernisation stack

A migration path that doesn't burn a quarter.

Everything you need to leave the legacy behind on your terms.

CA discovery
Find every issuer — known, unknown, and shadow.
  • Active + passive scan
  • Issuer graph
  • Risk scoring
ADCS bridge
Coexist with Microsoft ADCS during migration.
  • Auto-enrolment proxy
  • GPO integration
  • Zero downtime
Legacy CA plane
Bridge EJBCA, Vault, DigiCert into one control plane.
  • Unified policy
  • Single audit log
  • Central inventory
Crypto agility
Retire SHA-1 and RSA-1024 on next renewal.
  • Algorithm allow-lists
  • Auto-upgrade on renewal
  • Deprecation tracking
PQC readiness
Deploy hybrid classical + post-quantum today.
  • ML-KEM, ML-DSA
  • Hybrid certificates
  • Migration planner
Cloud-native ops
Kubernetes-first deployment on your infra.
  • Helm charts
  • Multi-cluster
  • GitOps compatible

From modernisation programmes

6 mo
Typical ADCS retirement path
0
Downtime during coexistence
100%
Legacy CA visibility after discovery
PQC
Ready today, deployed tomorrow
Case study
Fortune 500 · Legacy PKI migration

Retired 12 ADCS forests without a single service revalidation.

We were staring at a $4M ADCS refresh project. TigerTrust bridged the forests in six weeks and let us decommission on the audit committee timeline. The refresh never happened.
Enterprise PKI Architect
12
ADCS forests retired
6 mo
End-to-end migration
0
Downtime during coexistence
Integrations

Fits your existing stack

HSMs, legacy CAs, and public CA vendors that every modernisation programme has to bridge.

Thales Luna
HSM
Entrust nShield
HSM
YubiHSM 2
HSM
AWS CloudHSM
HSM
Microsoft ADCS
Legacy CA
EJBCA
Legacy CA
HashiCorp Vault
Legacy CA
AWS ACM PCA
Cloud CA
DigiCert CertCentral
Public CA
Sectigo
Public CA
GlobalSign
Public CA
Let's Encrypt / ACME
Public CA
FAQ

Frequently asked questions

TigerTrust runs an auto-enrolment proxy that speaks the ADCS wire protocol to Windows clients. Clients keep requesting from ADCS as they always did; TigerTrust intercepts, applies central policy, and either forwards to ADCS or fulfils from its own CA. GPO changes are minimal. From the desktop's perspective, nothing has changed. From the security team's perspective, one policy engine now governs both old and new.
Yes. For each workflow you migrate, TigerTrust issues in parallel with the legacy CA. Both certs are validated in production shadow mode; only when the modern-issued cert passes every check does traffic actually cut over. If regressions appear, rollback to the legacy path is instant. This is how customers migrate mission-critical workflows without a maintenance window.
Discovery flags every leaf and intermediate using deprecated algorithms with age, owner, and blast radius. Policy engine blocks new issuance in weak suites at the CA layer. On next renewal, TigerTrust upgrades to your approved allow-list (RSA-3072 minimum, ECDSA P-256 or better). Weak crypto retires on renewal rather than through a big-bang re-issuance.
TigerTrust is crypto-agile from day one. You can issue hybrid classical + post-quantum certificates today (ML-KEM for key encapsulation, ML-DSA for signatures alongside RSA / ECDSA). The migration planner shows which endpoints are ready for PQC, which are stuck on legacy suites, and sequences the root rotation. The next transition is a schedule item, not a project.
For a mid-sized ADCS estate (5–15 forests, 50k–500k certs), 4–8 months end to end. Weeks 1–4: discovery and coexistence bridge deployment. Weeks 5–12: per-workflow migration with parallel validation. Weeks 13+: legacy CA decommissioning on your schedule. The workload is discovery-driven — TigerTrust reports what depends on ADCS before you commit to a cutover.
Yes. Some CAs stay for good reasons — regulatory constraints, customer-mandated public CA relationships, or dedicated HSM investments. TigerTrust's coexistence layer is a permanent operating mode, not just a migration phase. You get central policy and inventory over whatever mix of CAs your business requires, without forcing a full consolidation.

Retire the legacy CA without the big-bang risk.