Nieuwsbrief
Ontvang je het KeyTalk nieuws liever direct in je mailbox? Meld je dan aan voor onze nieuwsbrief!
* Belangrijke ondersteuningsmededeling *
Vanwege noodzakelijk lokaal onderhoud aan onze KeyTalk Netwerkomgeving
zal de KeyTalk Cloud-omgeving niet toegankelijk zijn voor onze klanten.
Het onderhoud zal plaatsvinden van 12:30 tot 14:30 UTC
Dit bericht zal worden bijgewerkt met meer informatie zodra deze beschikbaar is.
Als je hierover vragen of opmerkingen hebt, neem dan contact met ons op via telefoon of e-mail.
KeyTalk / Support
Vragen?
Heb je specifieke vragen? Misschien helpen de veelgestelde vragen of downloads je verder.
Andere vragen, of ben je gewoon benieuwd wat KeyTalk voor jouw organisatie kan betekenen? Neem gerust contact met ons op. We denken graag met je mee.
We bieden onze klanten ook 24/7 ondersteuning.
Kan KeyTalk certificaten van meerdere certificeringsinstanties (CA's) verwerken?
Ik wil een Certificate Authority gebruiken, maar KeyTalk lijkt dit niet te ondersteunen! Is dit wel mogelijk?
Kan KeyTalk asymmetrische publieke/private cryptosleutels beheren?
Ondersteunt KeyTalk kortstondige X.509-certificaten?
Onze definitie van X.509-certificaten met een korte levensduur: certificaten die niet langer meegaan dan de tijd die nodig is om een huidige Certificate Revocation List (CRL) bij te werken en te verspreiden vanaf het moment dat ze zijn uitgegeven. Werkt u normaal gesproken met CRL’s die één keer per dag worden bijgewerkt? Dan zijn certificaten met een korte levensduur 24 uur korter geldig. Online Certificate Status Protocol (OCSP) radiatoren zijn theoretisch veel sneller te updaten dan CRL’s, maar in de praktijk duurt het meestal langer dan de gemiddelde tijd om een CRL te updaten om de noodzaak van het opnemen van een certificaat in een OCSP vast te stellen tot en met het daadwerkelijk opnemen van een certificaat in een OCSP. Dit betekent dat OCSP’s meestal niet praktischer zijn dan een CRL als het gaat om X.509-certificaten met een korte levensduur.
KeyTalk kan een willekeurige geldigheidsduur toekennen aan een uit te geven certificaat, als de doelcertificaatautoriteit dit ondersteunt. De kortste geldigheid die KeyTalk aan een certificaat kan toekennen is 1 seconde.
Downloads
Windows: Enterprise KeyTalk agent
Version: 8.1.3
About
Download: Default
Hashcode: SHA256: 9521a254f3df3f833bc75b4830353862a17fa8104c39d5066b388ac970ce9d34
KeyTalk Enterprise agent 8.1.3 brings the latest KeyTalk functionality to Windows 11, as well as Windows Server 2016 – 2025 supporting any server application you can provide a custom script for.
All default Windows certificate store supporting browsers are supported including Google Chrome, Microsoft IE, Edge, Opera, Brave, and Safari.
Secure Email Service Windows agent
Version: 8.1.3
About
Download: Default
Hashcode: SHA256: f674f13b466ec416e833eca648643af9801cbf1bf0e623ecfb3fa4b5f42ebc9d
► Manual
Our latest simplified agent for Windows adds support for automated recent and historic Shared Mailbox S/MIME fetching, installation and configuration for Classic Outlook.
Two versions are offered. One containing technology to discover and collect Authentication, S/MIME and/or TLS certificates and keys. AND one version not containing this discovery and collection technology.
__PRESENT
__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT
KeyTalk agent for Mac
Version: 7.9.0
About
Download: App Store
Hashcode: n.a.
KeyTalk agent for Mac version 7.9.0 brings the latest KeyTalk functionality to Apple’s OSX devices.
It supports the latest CA/B forum requirement for public trusted S/MIME issuance.
Our optional hardware recognition adds an additional factor on top of your existing authentication. This client is compatible as of KeyTalk virtual appliance 7.9.0.
Download the most recent DMG here SHA256: 51874912bd9fbbdbd7dcea6bd78c9ff90085647fd8187cd0c7700ee225bdd38f
Download the most recent PKG here SHA256: c858d75129ba5168a3d336d5430bfa2a8383ee6be4c89ade07a7eb3d070db27d
__PRESENT
Linux en Apache/TomCat KeyTalk-agent
Version: 7.9.0
About
Download: Default
Hashcode: SHA256: cd9a1dc81889b26f22c480c2e9bec39ff2c364c095087f30e679ac4341dd1d03
KeyTalk’s command prompt client 7.9.0 brengt KeyTalk uitgegeven en beheerde certificaten naar verschillende Linux OS.
7.9.0 voegt ondersteuning toe voor Ubuntu 24.04 incl. TPM sleutel attestatie, en update de Ubuntu 22.04 agent om ook de nieuwste TPM’s te ondersteunen.
KeyTalk’s optionele hardware herkenning maakt gebruik van je bestaande authenticatie, en stelt je in staat om eenvoudig BYOD en zakelijke apparaten te herkennen zodat ze alleen behoren tot specifieke werknemers, partners en klanten.
KeyTalk virtual application server OVF/VMDK for VMware and AWS
Version: 8.1.4
About
Download: Default
Hashcode: SHA256: 7e885023d26da48f41cddae97d6b876b6c4b572ba9f72711626b1ad17a34adfa
KeyTalk 8.1.4 (ZIP = 18.1 GB) virtual appliance (Ubuntu 24.04 Pro based, license through KeyTalk ) in OVF/VMDK format brings you the latest KeyTalk X.509 certificate automated life-cycle management and seamless enrollment for client, server and Internet of Things devices. For your internal private CA’s and public CA’s.
Use it to automate replacing your X.509 certificates on any device, and always have up to date strong keys and certificate meta data in your SSL/TLS certificates.
Customers and partners can install this virtual appliance onto their VMWare ESXi environment.
For AWS, simply login to your AWS account, search in public AMI for KeyTalk and launch the KeyTalk CKMS AMI from any region.
Need a production or trial license? Just contact your preferred KeyTalk partner or email us, and we will have you up and running in no time.
To decrypt any created encrypted native KeyTalk backups or Problem reports, you will need a Linux system running this AES-256-GCM decryption tool.
Do check if a new firmware update exists on this page to upgrade this virtual appliance to the latest greatest version.
For High Availablity clustering, you will need a Load Balancer and a MySQL DB to store the shared data between multiple KeyTalk virtual appliance front-ends.
The latest single (ie non-clustered) stand-alone MySQL 8 virtual appliance (ZIP 4.03 GB), compatible as of KeyTalk firmware 8.1.4 can be downloaded here. SHA256: 439f52c40b7782241bda3e64b64a346bbb991f88b35da67cf137bf0854806db6
Should you already have a single or clustered MySQL DB in your network, or wish to make use of an Azure Flexi Server, you can use this documentation to setup your own DB.
__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT__PRESENT
__PRESENT
__PRESENT
__PRESENT
KeyTalk virtual application server VHD for Azure and Hyper-V
Version: 8.1.4
About
Download: Default
Hashcode: SHA256: 8abecbfe4801f67c7bc4e0484ba482e1f13c7171b0638b94e8775f8d47ed43a6
KeyTalk 8.1.4 (ZIP = 14.9 GB) virtual appliance (Ubuntu 24.04 Pro license through KeyTalk) in VHD (GEN-1 DISK) format brings you the latest KeyTalk X.509 certificate automated life-cycle management and seamless enrollment to client, server and Internet of Things devices. For your internal private CA’s and public CA’s.
Use it to automate replacing your X.509 certificates on any device, and always have up to date strong keys and certificate meta data in your SSL/TLS certificates.
Customers and partners can install this virtual appliance onto their Hyper-V and Azure environment.
Need a production or trial license? Just contact your preferred KeyTalk partner or email us, and we will have you up and running in no time.
To decrypt any created encrypted native KeyTalk backups or Problem reports, you will need a Linux system running this AES-256-GCM decryption tool.
Do check if a new firmware update exists on this page to upgrade this virtual appliance to the latest greatest version.
For High Availablity clustering, you will need a Load Balancer and a MySQL DB to store the shared data between multiple KeyTalk virtual appliance front-ends.
The latest single (ie non-clustered) stand-alone MySQL 8 virtual appliance (ZIP 2.5 GB), compatible as of KeyTalk firmware 8.1.4 can be downloaded here. SHA256: fe60cd143db2b68b804d94f1bee665577ee7cc38350309c305857e62afcc9d77
Should you already have a single or clustered MySQL DB in your network, or wish to make use of an Azure Flexi Server, you can use this documentation to setup your own DB.
__PRESENT
KeyTalk firmware upgrade
Version: 8.1.3
About
Download: Default
Hashcode: SHA256: 1e60651536596390243aca0eafa069fe7c2907437f67f73c9efad579c51e72e4
KeyTalk’s 8.1.3 firmware update (1.08GB) , upgrades your KeyTalk 8.x virtual appliance to the latest v8 production release .
It additionally updates your connected KeyTalk MySQL Db tables provided it is connected to the KeyTalk virtual appliance you upload this firmware update to.
This update adds various stability updates.
To test with KeyTalk CLM issued PQC certificates (ML-DSA / ML-KEM), use Windows Server 2025 IIS, or you can make use of our pre-configured NGINX PQC docker image. It can be downloaded here. SHA256: 40bde801a2f617d6120b0fec516305f95cef78daeb5e5b61eccc7972e26148ae
For the full details of this release: please read the Release Notes.
Before upgrading always back-up / snap-shot your KeyTalk environment (server and Db)!
Need the last KeyTalk 7.1.3 firmware (1.04 GB), you can download it here.
Need the last KeyTalk 6.6.3 firmware (720 MB), you can download it here.
__PRESENT
__PRESENT
__PRESENT
__PRESENT
__PRESENT
__PRESENT
__PRESENT
__PRESENT
__PRESENT
KeyTalk API as of firmware
Version: 8.1.4
About
Download: Default
Hashcode: SHA256: bdb908b3c44c7e002e820843b91a8c32ed1ff259e93b4e18b377b5ff5aae6cdc
KeyTalk’s modern API gives app and software developers maximum freedom to incorporate secure encrypted data-in-motion and authentication to a suitable backend into their own software.
The KeyTalk client API is typically used to ensure end-points receive their certificate (and key) and is also used in our client software. Our RESTful API makes use of JSON calls over TLS making it lightweight and easy to add to any existing code.
The OpenAPI spec can also be found here: https://downloads.keytalk.com/downloads/OpenAPI/swagger-ui.html
Those who prefer redoc can find the OpenAPI spec here: https://downloads.keytalk.com/downloads/OpenAPI/redoc.html
You can find a sample Python code on how to potentially add the KeyTalk public REST API to your own code here: sample code
__PRESENT
__PRESENT
__PRESENT
S/MIME LDAP secure email address book
Version: 5.7.0
About
Download: Default
Hashcode: b41c4d112e63123f41e9aa9796f09ab5bdad697911e61ec1a9e0ec563fdded43
KeyTalk’s S/MIME LDAP secure email address book virtual appliance (2 Gb download), is an OpenLDAP based hardened LDAP running CentOS 7, optimized for the sole purpose of LDAP(S) and HTTPS based lookups of public certificate details for S/MIME secure email purposes.
This virtual appliance also seamlessly integrates with the KeyTalk virtual appliance for publicizing issued S/MIME email encryption client certificate public details for communities of 2 certificates up to dozen of millions.
Need a production or trial licence? Just contact your preferred KeyTalk partner or email us, and we will have you up and running in no time.
SSL Certificate Discovery Smart Security Scanner
Version: 6.4.2
About
Download: Default
Knowing exactly which SSL/TLS certificates you have port-bound in your network is often a challenge, even for the die-hard network managers. Let alone determining what certificates are present locally on servers and user-devices.
KeyTalk’s Enterprise Network SSL Smart Security Scanner goes well beyond NMap and other commonly used scan tools, and includes a network CVE scanner.
It provides you with insights of your network SSL/TLS vulnerabilities, informs you of all scannable X.509 certificates and their relevant meta-data, and can optionally scan for other known network vulnerabilities. The scan result data is provided to you locally only, in raw JSON as well as in a directly usable management report in HTML, and can be automatically send to a target KeyTalk Certificate and Key Management Solution server for analysis and certificate management purposes.
This OVF/VMDK download is 10.2 GB in size (zip) and available for VMWare
Active Directory AltSecurityIdentity update script
About
Download: Default
► Manual
Microsoft solutions, such as OWA and SharePoint, natively support client certificate based authentication. It additionally requires a reference to the client certificate in the AD AltsecurityIdentity attribute.
KeyTalk can automatically write/update this client certificate information to your AD in the appropriate attribute.
However some Admins as a policy do not allow third party software to make these needed meta data updates in their AD.
This PowerShell script acts as an example, enabling an Admin to populate their AD with the relevant data in order for client certificates to be properly mapped to AD users.