Sectigo Blog

When & How to Use Sectigo's Private PKI Solutions

Leveraging a public root delivers instant universal trust across your user base. An organization may also have servers that are not external-facing and don't need publicly rooted certificates. These servers, however, may still need authentication, signing, and capability, to establish a secure TLS session with other internal servers or applications. This post explains three deployment architectures to consider for using Sectigo Private PKI.

Figure 1. Sectigo-Hosted Private PKI
Figure 2. Customer-Hosted Root CA with Sectigo-Hosted Issuing CA
Figure 3. Sectigo-Hosted Root CA with Customer-Hosted Issuing CA