Fixed Price

Certificate-Based Authentication

Map X.509 client certificates to Keycloak users for device-bound, passwordless Single Sign-On (SSO). Managed devices log in without friction. Unmanaged devices are hard-blocked before they reach a login page.

·2-3 weeks

Overview

We connect Keycloak to the certificate infrastructure you already have (ADCS, Keyfactor, EJBCA, or any cloud Certificate Authority) and configure it to authenticate users by their device certificates, not passwords. The engagement covers mutual TLS (mTLS) proxy setup, certificate-to-user mapping using Subject Distinguished Names and Subject Alternative Names, revocation checking via Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL), a guided device enrollment flow, and a fallback authentication path for helpdesk resets. Runbooks and operations documentation are included so your team can own it after handoff. Once live, managed devices access your internal applications with no password prompt. Unmanaged devices have no credential path to protected resources, and a revoked device certificate is blocked within minutes. This works best for enterprises with existing Public Key Infrastructure (PKI) that need a hard boundary between managed and unmanaged device access. Organizations on Keyfactor get centralized certificate lifecycle management on top, with issuance and revocation handled in one place across all enrolled devices. The same setup supports smart card authentication (PIV and CAC cards) for environments that require hardware-bound credentials.

Delivery Process

Presents CertOCSP / CRLMap to UserToken IssuedAuthorizedManaged DevicemTLS ProxyCert VerifiedKeycloak AuthSSO TokenInternal App

What's Included

  • X.509 certificate-to-user mapper (Subject DN / Subject Alternative Name)
  • Mutual TLS (mTLS) termination config (Nginx / HAProxy)
  • Certificate revocation via OCSP and CRL
  • Device enrollment flow
  • Fallback authentication flow
  • Runbook and operations documentation

Timeline & Scope

Timeline

2-3 weeks

Ideal For

Enterprises with existing PKI, ADCS or Keyfactor wanting passwordless, device-bound SSO for internal apps.

Warranty

30-day warranty covering certificate mapping accuracy, revocation check failures, and fallback flow issues discovered after deployment.

Tech Stack

Keycloak 26.xX.509 / mTLSNginx / HAProxyOCSP / CRLJava SPIKeyfactor (optional)

Ready to get started?

Fixed price. Clear scope. 30-day warranty.

Or view all service packages