Generate CSRs, complete them once your CA issues the certificate, repair broken private-key links, and export - all against the Windows Certificate Store. Works with whatever CA you already use.
Certificate Manager covers the generation and key-management side of the certificate lifecycle - the counterpart to Certificate Validator's validation side. Generate a new key and CSR, complete the request once a certificate authority issues the certificate, import an already-combined .pfx from elsewhere, diagnose and repair broken private-key links, and export to .pfx or .cer. It isn't tied to any single CA's account or ordering system - it works with whatever certificate authority your organization already has a relationship with.
New key + CSR from your Subject and SAN fields - RSA (2048/3072/4096) or EC (P256/P384), targeting the Current User or Local Machine store, with an exportable-key flag that defaults off.
Bind a CA-issued certificate back to its pending CSR's private key - works with any CA - or directly import an already-combined .pfx from elsewhere.
A real sign-and-verify test of a certificate's private key - not just a presence check - plus one-click repair of broken key associations and store-location mismatches.
Export to a password-protected .pfx or public-only .cer, and view any certificate - including its full certification path - in Windows' own viewer.
Generate a whole folder of saved requests in one run, enforce your own minimum key size and required fields before generation, and browse every past action.
Register a daily Windows Task Scheduler run that checks every store certificate's key health, or drive it from your own scripts with CertificateManager.exe --create-csr/--complete/--repair/--export/--scan-health.
Pick how much automation you need, then choose once-off or monthly billing. Certificate Manager licenses per machine, not by certificate volume.
One-time payment - yours to keep, no subscription.
For handling one request at a time.
Single CSR generation, completion, import, export, repair, and view - full detail on screen.
For handling many requests at once.
Everything in Standard, plus batch CSR generation from a saved folder of requests and CSV export.
For enforcing your own request standards.
Everything in Standard+, plus custom policy profiles and persisted request history across time.
For fully unattended key hygiene.
Everything in Advanced, plus scheduled key-health scans, a headless CLI, and renewal handoff.
All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.
Standard covers the core of Certificate Manager: generate a CSR, complete a request once a CA issues the certificate, import an existing .pfx, repair a broken key, export, or view - one at a time, full detail on screen. No batch, history, or automation at this tier, by design.
Best for: Anyone handling a certificate request or two at a time.
Standard+ adds batch CSR generation - point it at a folder of saved request specs and generate them all in one run - plus CSV export of request history for reporting. Everything from Standard is included.
Best for: Anyone provisioning certificates for more than a handful of servers at once.
Advanced adds custom policy profiles - enforce your own minimum key size, required Organizational Unit, and allowed SAN patterns before a CSR is ever generated - plus request history, so you can review every generate/complete/import/export/repair action over time. Everything from Standard+ is included.
Best for: Teams enforcing their own internal request standards, not just accepting whatever gets typed in.
Professional adds scheduled key-health scans (a daily Windows Task Scheduler run that checks every store certificate's private-key health), a headless CLI (CertificateManager.exe --create-csr/--complete/--repair/--export/--scan-health), and renewal handoff - soon-expiring store certificates flagged with a prefilled renewal CSR ready to review and generate. Everything from Advanced is included.
Best for: Organizations that need certificate key hygiene genuinely enforced on a schedule, not just handled reactively.
Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.