SYSTEM TOPOLOGY & RESILIENCE

Enterprise High-Availability System Architecture

Distributed execution engine, cross-region resilience, and full air-gapped capability with zero external dependency.

CertCycle 3-Tier Distributed Architecture

Central Policy Core, Encrypted Dispatchers, and Endpoint Targets

Central Management Engine

Policy engine, scheduling coordinator, multi-CA API connectors, and automated notification subsystem.

AES-256 Key & Certificate Vault Cryptographic Policy Engine GlobalSign & ACME Connectors
Secure Execution Layer

Encrypted worker channels, WinRM/SSH task dispatchers, and fault-tolerant queue management.

mTLS Encrypted RPC Bus Agentless WinRM & SSH Dispatcher Distributed Task Queue
Target Edge & Infrastructure

Web servers, load balancers, firewalls, API gateways, and specialized enterprise services.

IIS Servers & Exchange Linux Nginx / Apache / HAProxy F5 BIG-IP & FortiGate Firewalls

Agentless Architecture (WinRM & SSH)

Manage target infrastructure without installing software agents on endpoints.

  • PowerShell Remoting & WinRM over HTTPS (Port 5986) for Windows
  • OpenSSH Public Key Authentication for Linux/Unix
  • REST APIs & vendor SDKs for F5, FortiGate, and Kemp appliances

Lightweight Agent (CertCycle Client)

Purpose-built lightweight Windows Service and Linux daemon for locked-down or NAT-isolated environments.

  • Ultra low footprint (<25 MB RAM) and zero background CPU overhead
  • Outbound-only mTLS channel over TLS 1.3 (no open inbound ports)
  • Automatic local Windows Certificate Store & IIS binding management