Bulletin d'information

Préférez-vous recevoir les nouvelles de KeyTalk directement dans votre boîte aux lettres ? Inscrivez-vous à notre bulletin d’information !

* Avis de support important

En raison d’une maintenance locale nécessaire sur notre environnement KeyTalk Network
, l’environnement KeyTalk Cloud ne sera pas accessible à nos clients.

La maintenance est prévue de 12h30 à 14h30 (UTC).


Le présent avis sera mis à jour avec de plus amples informations dès qu’elles seront disponibles.
Si vous avez des questions ou des préoccupations à ce sujet, n’hésitez pas à nous contacter par téléphone ou par courrier électronique.

Des questions ?

Vous avez des questions spécifiques ? La foire aux questions ou les téléchargements vous aideront peut-être.

Vous avez d’autres questions ou vous vous demandez simplement ce que KeyTalk peut faire pour votre organisation ? N’hésitez pas à nous contacter. Nous serions ravis d’y réfléchir ensemble.

Nous offrons également à nos clients une assistance 24 heures sur 24 et 7 jours sur 7.

Oui, KeyTalk peut gérer plusieurs autorités de certification. Il peut s’agir d’autorités de certification privées, telles que le serveur de certificats Microsoft Active Directory, ou d’autorités de certification publiques, telles que GMO GlobalSign ou DigiCert QuoVadis.
Oui, KeyTalk développe des fonctionnalités et des intégrations en fonction de la demande des clients et de l’analyse de rentabilité. Lorsqu’une intégration requise n’est pas encore prise en charge et qu’elle est techniquement réalisable, vous pouvez rendre possible une intégration réussie en collaboration avec l’unité commerciale de KeyTalk. Cette intégration sera alors intégralement incorporée dans notre logiciel et sera donc également maintenue.
Oui, KeyTalk peut générer des clés privées avec une entropie suffisante, dans le cadre des demandes de signature de certificats (CSR) générées de manière centralisée. Ces paires de clés asymétriques peuvent être stockées dans sa propre base de données de gestion cryptée AES256 ou dans un module de sécurité matériel (HSM) lié. Dès qu’une paire de clés expire ou devient invalide, la plate-forme KeyTalk régénère cette paire de clés et le certificat associé, soit automatiquement, soit de manière semi-automatique par le biais d’un processus de flux de travail.

Notre définition des certificats X.509 à courte durée de vie : les certificats qui ne durent pas plus longtemps que le temps nécessaire à la mise à jour et à la distribution d’une liste de révocation de certificats (CRL) à partir du moment où ils ont été émis. Vous travaillez normalement avec des CRL qui sont mises à jour une fois par jour ? Dans ce cas, les certificats à durée de vie courte sont valables 24 heures de moins. Les radiateurs OCSP (Online Certificate Status Protocol) sont théoriquement beaucoup plus rapides à mettre à jour que les CRL, mais dans la pratique, il faut généralement plus de temps que le temps moyen de mise à jour d’une CRL pour établir la nécessité d’inclure un certificat dans un OCSP, jusqu’à l’inclusion effective d’un certificat dans un OCSP. Cela signifie que les OCSP ne sont généralement pas plus pratiques qu’une CRL lorsqu’il s’agit de certificats X.509 de courte durée.

KeyTalk peut attribuer n’importe quelle durée de vie à un certificat à émettre, dans la mesure où l’autorité de certification cible le prend en charge. La durée de validité la plus courte que KeyTalk peut attribuer à un certificat est de 1 seconde.

Téléchargements

Windows: Enterprise KeyTalk agent

Version: 7.9.3

Download: Default

Hashcode: SHA256: a2db9d368a51b33601df5c8cb00b8ce2bd976bbac43a53a04fbef40d8b9d98c6

KeyTalk Enterprise agent 7.9.3 brings the latest KeyTalk functionality to Windows 11, as well as Windows Server 2016 – 2022 with IIS 10 and IBM WebSphere 9.x and any other application you can provide a custom PowerShell script for.

All default Windows certificate store supporting browsers are supported including Google Chrome, Microsoft IE, Edge, Opera, Brave, and Safari.

Secure Email Service Windows agent

Version: 7.9.3

Download: Default

Hashcode: SHA256: 48184d192427662435c678aba3be6f89dc9484c519e1db05d1b26b29899409bb

► Manual

Our latest simplified agent for Windows adds support for automated recent and historic Shared Mailbox S/MIME fetching, installation and configuration for Classic  Outlook.

Two versions are offered. One containing technology to discover and collect Authentication, S/MIME and/or TLS certificates and keys. AND one version not containing this discovery and collection technology.

__PRESENT

KeyTalk agent for Mac

Version: 7.9.0

Download: App Store

Hashcode: n.a.

KeyTalk agent for Mac version 7.9.0 brings the latest KeyTalk functionality to Apple’s OSX devices.

It supports the latest CA/B forum requirement for public trusted S/MIME issuance.

Our optional hardware recognition adds an additional factor on top of your existing authentication. This client is compatible as of KeyTalk virtual appliance 7.9.0.

Download the most recent DMG here SHA256: 51874912bd9fbbdbd7dcea6bd78c9ff90085647fd8187cd0c7700ee225bdd38f

Download the most recent PKG here SHA256: c858d75129ba5168a3d336d5430bfa2a8383ee6be4c89ade07a7eb3d070db27d

 

__PRESENT

__PRESENT

Apple’s iOS KeyTalk client

Version: 7.4.0

Download: App Store

Hashcode: SHA256: B24426A42F661142E8760829FF16028D149EAE4822162D7FE078AC7EC26BD7F5

KeyTalk client 7.4.0 for iOS brings KeyTalk’s certificate distribution functionality to Apple’s iPad and iPhone as of iOS 10.3

KeyTalk’s optional hardware recognition leverages your existing authentication and enables you to easily recognize BYOD and Corporate devices to belong to only specific employees, partners, and customers.

Should an IPA be required that incorporates your KeyTalk configuration(s) for easy distribution by means of your MDM solution, it can be downloaded here.

__PRESENT

__PRESENT

Linux et Apache/TomCat Agent KeyTalk

Version: 7.9.0

Download: Default

Hashcode: SHA256: cd9a1dc81889b26f22c480c2e9bec39ff2c364c095087f30e679ac4341dd1d03

Le client d’invite de commande 7.9.0 de KeyTalk apporte les certificats émis et gérés par KeyTalk à divers systèmes d’exploitation Linux.

7.9.0 ajoute la prise en charge d’Ubuntu 24.04, y compris l’attestation de clé TPM, et met à jour l’agent Ubuntu 22.04 pour prendre également en charge les derniers TPM.

La reconnaissance matérielle optionnelle de KeyTalk tire parti de votre authentification existante et vous permet de reconnaître facilement les appareils BYOD et d’entreprise pour qu’ils n’appartiennent qu’à des employés, partenaires et clients spécifiques.

KeyTalk virtual application server OVF/VMDK for VMware and AWS

Version: 8.1.0

Download: Default

Hashcode: SHA256: ffae15493cadd31068c59d86ac4b0c05dbeec72a95a6a4e1eb9cd0bbadb5a2c4

KeyTalk 8.1.0 (ZIP = 12.5 GB) virtual appliance (Ubuntu 24.04 Pro based, license through KeyTalk ) in OVF/VMDK format brings you the latest KeyTalk X.509 certificate automated life-cycle management and seamless enrollment for client, server and Internet of Things devices. For your internal private CA’s and public CA’s.

Use it to automate replacing your X.509 certificates on any device, and always have up to date strong keys and certificate meta data in your SSL/TLS certificates.

Customers and partners can install this virtual appliance onto their VMWare ESXi environment.

For AWS, simply login to your AWS account, search in public AMI for KeyTalk and launch the KeyTalk CKMS AMI from any region.

 

Need a production or trial license? Just contact your preferred KeyTalk partner or email us, and we will have you up and running in no time.

To decrypt any created encrypted native KeyTalk backups or Problem reports, you will need a Linux system running this AES-256-GCM decryption tool.

Do check if a new firmware update exists on this page to upgrade this virtual appliance to the latest greatest version.

 

For High Availablity clustering, you will need a Load Balancer and a MySQL DB to store the shared data between multiple KeyTalk virtual appliance front-ends.

The latest single (ie non-clustered) stand-alone MySQL 8 virtual appliance (ZIP 5.16 GB), compatible as of KeyTalk firmware 8.1.0 can be downloaded here.

Should you already have a single or clustered MySQL DB in your network, or wish to make use of an Azure Flexi Server, you can use this documentation to setup your own DB.

__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT

__PRESENT

__PRESENT

KeyTalk virtual application server VHD for Azure and Hyper-V

Version: 8.1.0

Download: Default

Hashcode: SHA256: 2858ed400fb9dc62fb801849c8596ddad539593de1e061bf45f3123725b51c5d

KeyTalk 8.1.0 (ZIP = 10.3 GB) virtual appliance (Ubuntu 24.04 Pro license through KeyTalk) in VHD (GEN-1 DISK) format brings you the latest KeyTalk X.509 certificate automated life-cycle management and seamless enrollment to client, server and Internet of Things devices. For your internal private CA’s and public CA’s.

Use it to automate replacing your X.509 certificates on any device, and always have up to date strong keys and certificate meta data in your SSL/TLS certificates.

Customers and partners can install this virtual appliance onto their Hyper-V and Azure environment.

 

Need a production or trial license? Just contact your preferred KeyTalk partner or email us, and we will have you up and running in no time.

To decrypt any created encrypted native KeyTalk backups or Problem reports, you will need a Linux system running this AES-256-GCM decryption tool.

Do check if a new firmware update exists on this page to upgrade this virtual appliance to the latest greatest version.

 

For High Availablity clustering, you will need a Load Balancer and a MySQL DB to store the shared data between multiple KeyTalk virtual appliance front-ends.

The latest single (ie non-clustered) stand-alone MySQL 8 virtual appliance (ZIP 7.66GB), compatible as of KeyTalk firmware 8.1.0 can be downloaded here.

Should you already have a single or clustered MySQL DB in your network, or wish to make use of an Azure Flexi Server, you can use this documentation to setup your own DB.

__PRESENT

KeyTalk firmware upgrade

Version: 8.1.3

Download: Default

Hashcode: SHA256: 1e60651536596390243aca0eafa069fe7c2907437f67f73c9efad579c51e72e4

KeyTalk’s 8.1.3 firmware update (1.08GB) , upgrades your KeyTalk 8.x virtual appliance to the latest v8 production release .

It additionally updates your connected KeyTalk MySQL Db tables provided it is connected to the KeyTalk virtual appliance you upload this firmware update to.

This update adds various stability updates.

To test with KeyTalk CLM issued PQC certificates (ML-DSA / ML-KEM), use Windows Server 2025 IIS, or you can make use of our pre-configured NGINX PQC docker image.  It can be downloaded here. SHA256: 40bde801a2f617d6120b0fec516305f95cef78daeb5e5b61eccc7972e26148ae

For the full details of this release: please read the Release Notes.

Before upgrading always back-up / snap-shot your KeyTalk environment (server and Db)!

Need the last KeyTalk 7.1.3 firmware (1.04 GB), you can download it here.

Need the last KeyTalk 6.6.3 firmware (720 MB), you can download it here.

__PRESENT

__PRESENT

__PRESENT

__PRESENT

__PRESENT

__PRESENT

__PRESENT

__PRESENT

__PRESENT

KeyTalk API as of firmware

Version: 8.1.3

Download: Default

Hashcode: SHA256: bdb908b3c44c7e002e820843b91a8c32ed1ff259e93b4e18b377b5ff5aae6cdc

KeyTalk’s modern API gives app and software developers maximum freedom to incorporate secure encrypted data-in-motion and authentication to a suitable backend into their own software.

The KeyTalk client API is typically used to ensure end-points receive their certificate (and key) and is also used in our client software.

KeyTalk’s admin API is typically used to automate certificate management from a target system such as Service Now, or on a management system proxy.

KeyTalk’s Outbound Management API spec describes how third party certificate providers can provide their own API interface code for KeyTalk to easily integrate into its products. Enabling integration with any certificate provider in the world with minimal effort.

Our RESTful API makes use of JSON calls over TLS making it lightweight and easy to add to any existing code.

Additionally the API allows any developer to determine their own hardware footprint of a device, contrary to KeyTalk’s clients which enforce specific hardware/software characteristics.

You can find a sample Python code on how to potentially add the KeyTalk REST API to your own code here: sample code

__PRESENT

__PRESENT

S/MIME LDAP secure email address book

Version: 5.7.0

Download: Default

Hashcode: b41c4d112e63123f41e9aa9796f09ab5bdad697911e61ec1a9e0ec563fdded43

KeyTalk’s S/MIME LDAP secure email address book virtual appliance (2 Gb download), is an OpenLDAP based hardened LDAP running CentOS 7, optimized for the sole purpose of LDAP(S) and HTTPS based lookups of public certificate details for S/MIME secure email purposes.

This virtual appliance also seamlessly integrates with the KeyTalk virtual appliance for publicizing issued S/MIME email encryption client certificate public details for communities of 2 certificates up to dozen of millions.

Need a production or trial licence? Just contact your preferred KeyTalk partner or email us, and we will have you up and running in no time.

SSL Certificate Discovery Smart Security Scanner

Version: 6.4.2

Download: Default

Knowing exactly which SSL/TLS certificates you have port-bound in your network is often a challenge, even for the die-hard network managers. Let alone determining what certificates are present locally on servers and user-devices.

KeyTalk’s Enterprise Network SSL Smart Security Scanner goes well beyond NMap and other commonly used scan tools, and includes a network CVE scanner.

It provides you with insights of your network SSL/TLS vulnerabilities, informs you of all scannable X.509 certificates and their relevant meta-data, and can optionally scan for other known network vulnerabilities. The scan result data is provided to you locally only, in raw JSON as well as in a directly usable management report in HTML, and can be automatically send to a target KeyTalk Certificate and Key Management Solution server for analysis and certificate management purposes.

This OVF/VMDK download is 10.2 GB in size (zip) and available for VMWare

Active Directory AltSecurityIdentity update script

Download: Default

► Manual

Microsoft solutions, such as OWA and SharePoint, natively support client certificate based authentication. It additionally requires a reference to the client certificate in the AD AltsecurityIdentity attribute.

KeyTalk can automatically write/update this client certificate information to your AD in the appropriate attribute.

However some Admins as a policy do not allow third party software to make these needed meta data updates in their AD.

This PowerShell script acts as an example, enabling an Admin to populate their AD with the relevant data in order for client certificates to be properly mapped to AD users.

Although we were one of the first customers to choose the combined S/MIME Management and Automation Service from GlobalSign & KeyTalk and we had to overcome some initial hurdles, we got fantastic support from the KeyTalk team and the service is working perfectly now. I would absolutely recommend their S/MIME Management and Automation Service to any company that needs easy-to-use end-to-end secure email communication. — Matteo Snidero, Head of IT @ Finance in Motion