Certificate-Based Authentication
Map X.509 client certificates to Keycloak users for device-bound, passwordless Single Sign-On (SSO). Managed devices log in without friction. Unmanaged devices are hard-blocked before they reach a login page.
Overview
We connect Keycloak to the certificate infrastructure you already have (ADCS, Keyfactor, EJBCA, or any cloud Certificate Authority) and configure it to authenticate users by their device certificates, not passwords. The engagement covers mutual TLS (mTLS) proxy setup, certificate-to-user mapping using Subject Distinguished Names and Subject Alternative Names, revocation checking via Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL), a guided device enrollment flow, and a fallback authentication path for helpdesk resets. Runbooks and operations documentation are included so your team can own it after handoff. Once live, managed devices access your internal applications with no password prompt. Unmanaged devices have no credential path to protected resources, and a revoked device certificate is blocked within minutes. This works best for enterprises with existing Public Key Infrastructure (PKI) that need a hard boundary between managed and unmanaged device access. Organizations on Keyfactor get centralized certificate lifecycle management on top, with issuance and revocation handled in one place across all enrolled devices. The same setup supports smart card authentication (PIV and CAC cards) for environments that require hardware-bound credentials.
Delivery Process
What's Included
- X.509 certificate-to-user mapper (Subject DN / Subject Alternative Name)
- Mutual TLS (mTLS) termination config (Nginx / HAProxy)
- Certificate revocation via OCSP and CRL
- Device enrollment flow
- Fallback authentication flow
- Runbook and operations documentation
Timeline & Scope
Timeline
2-3 weeks
Ideal For
Enterprises with existing PKI, ADCS or Keyfactor wanting passwordless, device-bound SSO for internal apps.
Warranty
30-day warranty covering certificate mapping accuracy, revocation check failures, and fallback flow issues discovered after deployment.
Tech Stack
Ready to get started?
Fixed price. Clear scope. 30-day warranty.