Khatim RA Server: Your Gateway to Trusted Certificate Lifecycle Management
Khatim Registration Authority Server (KRS) Server stands as a robust registration and vetting platform empowering Enterprises, Governments, and TSP to facilitate tailored enrollment and onboarding processes. KRS enforces stringent identity verification protocols, enhancing the overall security and integrity of your certificate life cycle management (CLM).
- Simplified multitenant enrollment
- Easily integrate using APIs, CMP, ACME & SCEP
- Provision low and high assurance X.509 certificates
- Issue certificates to individuals, devices and applications
- Compatible with Web Trust, IETF 5280, CA/B forum standards

Why choose Khatim RA Server?
Built for Enterprises
Ensures reliable issuance of high-volume X.509 certificate issuance across diverse business applications, devices, and individuals. Keeps full track of certificate request life cycle be it closed PKI, public or National PKI.
Multiple Vetting Options
Provides automated and manual vetting for high or low assurance certificates with single or multiple approvals. Performs CA/B forum based checks for quick issuance of certificates with zero delays.
IOT, People, Applications
Provides both API & GUI interfaces for devices, IOT, people & applications. Issue SSL Certificates (DV, OV, IV, EV), S/Mime (MV, OV, SV, IV), AATL or Qualified Certificates with SCEP, CMP, ACME & EST protocols.
How Khatim RA Server works?
Khatim RA Server (KRS) consist of 4 core components:
- Admin Portal: Access configs, transactions & statistics
- API: Provides RA services to business apps
- Diagnostic: Performs housekeeping and health checks
- Storage: Stores configurations and transactional data
The overall processing logic is quite simple:
- Send certificate request via business appss or admin portal
- KRS verifies the incoming request
- KRS interacts with Khatim PKI Server for certificate issurance
- KRS returns the issued certificate back to the client
-
Protects your PKI
Khatim RA server integrates with Khatim PKI Server handling all the complex user vetting process & acting as the first line of defense before sending the certification request to Khatim PKI. PKI admin can also configure multiple CAs with a single Khatim RA server. This offloads all validations, vetting to Khatim RA Server allowing Khatim PKI Server to manage the core PKI tasks i.e. certificate issuance, revocation etc. -
Auto Enrollment
Websites and devices need X.509 digital certificates and they need it quickly with no manual intervention. Khatim RA Server supports both ACME (rfc8555) to issue SSL Certificates for websites & SCEP for devices (routers, switches etc.). -
Setup Vetting Policies
Khatim RA Server allows customizable manual vetting by any number of RA Admin or LRA Admins or even no vetting for low assurance certificates. All admins can provide their vetting reports in any form, be it PDF, videos, images with notes. The complete vetting history is then maintained for audit purposes.
-
Developer Integrations
Want to control your RA from your CRM, ECM etc. No issues, with Restful APIs, business applications remain in command of their RA be it configurations, setting up organization, vetting, plans and more.
Deployment
-
Supported OS
All flavors of Windows Server & Linux (Centos Stream, Ubuntu, RedHat, Fedora)
-
Languages
50+ Languages (English, Chinese, French, Italian Spanish, Arabic, German, Portuguese etc.)
-
Minimum H/W Requirement
8 GB RAM, 2 vCPU (2.3 GHz), 10 GB disk space.
Words from Client
Leading companies rely on us for their PKI and digital signature needs
We needed the ability to use X.509 Certificate based SSL Client Authentication to provide an additional security layer for our cloud-based applications and Codegic not only quickly provisioned the certificates we needed, but also provided very responsive support when we had questions. Rolling out any PKI project can be hard work, but having a partner like Codegic has made it fast and easy.
Kevin de Smidt, Head of Technology, CURE International
Pricing
- Khatim RA Server is charged per bundle
- Each bundle allows you to deploy 2 instance of PKI server in high availability mode
- To add more servers in your existing pool; OR Buy a single server instance at 50% of the bundle price
- Test environments or Staging environments are charged 50% of the price
Maintenance Plan
With active annual software maintenance plan:
- Keep your installation safe and secure with the latest security updates
- Get free access to the newest features, enhancements, and bug fixes
- Get premium support from our technical engineers (within 24 hours on business days)
Has your maintenance expired?
Want to renew your maintenance plan? The price for 12 months is 25% of your license’s (current) list price.
Save more with extended supported
- Extend for 24 months and save 10%
- Extend for 36 months and save 15% best value
FAQs
How does Khatim RA Server ensure security during the enrollment process?
Khatim RA Server verifies user identities using various authentication methods and ensures data encryption during the transmission of sensitive information.
Does Khatim RA Server manage certificate revocation?
Khatim RA Server does not manage revocation directly. However, it facilitates revocation requests by verifying the identity of the requester before forwarding it to the CA for revocation.
Is it possible to integrate an Khatim RA Server with existing identity management systems?
Yes, Khatim RA Server can be integrated with existing identity and access management systems for seamless user authentication and validation.
Can I setup service plans against different organizations?
Yes. You can setup multiple certificate types and link them in service plan which are then assigned to different organizations. You can further control the number of to-be issued certificates and life time of a service plan.
To provision certificates on Smart Cards which protocol is supported?
Khatim RA server can provision X.509 certificate using RSA or ECDSA based keys for any smartcard or USB token which supports PKCS#11 interface. Almost all vendors support PKCS#11 interface.
Does Khatim RA Server have self-service features for users?
Yes it offers self-service capabilities, allowing users to initiate certificate requests, track their progress, and manage certificates.
Can an RA Server handle high volumes of certificate requests?
Yes, Khatim RA Servers are designed to efficiently manage high volumes of certificate requests, employing scalable architectures to handle increased demand without compromising performance.
Can Khatim RA Server issue certificates?
No, Khatim RA Server does not directly issue certificates. It validates user information, processes certificate requests, and sends verified requests to the Khatim PKI Server for certificate issuance.
How can I track all of my issued certificates?
Khatim RA Server provides multiple portals for RA Admins, LRA Admins and LRA Users to track and see the workflow and the list of issued, expired, revoked certificates along with detailed reports and charts. Certificate requestors are also notified for about to expire certificates.
