Auto-Enrollment Protocols

AppViewX CLM enables certificate auto-enrollment by automating all the steps involved, including CSR generation, domain ownership verification, certificate download, and provisioning, making the process efficient, scalable, and secure. AppViewX CLM supports all major auto-enrollment protocols including – ACME, EST, SCEP, Native Windows Auto-enrollment, and Microsoft Intune. Automating certificate enrollment reduces human error, outages, and security compromises, while improving productivity.

Auto-enrollment protocols are standardized enrollment mechanisms accepted across a wide range of enterprise systems for device and application certificate enrollment. Systems leveraging auto-enrollment protocols typically expect minimum to no admin intervention. Network devices such as routers-switches, DevOps tools, and Enterprise Mobility Management platforms are typical examples of such systems. If the deployment mode is:
  • SaaS or Managed Kubernetes, deploying a cloud connector enables auto-enrollment.
  • SaaS deployments where cloud connectors are unavailable, users should provide the AppViewX host information, which includes the IP address and port of the URL or endpoint. If their devices support auto-enrollment to a public URL, auto-enrollment is available as part of the tenant, and configuration details are provided in the documentation.

The cloud connector is advised for DMZ-based deployments or for enrollment through your cloud connector. This is especially useful in scenarios where endpoints cannot communicate with a public URL for auto-enrollment through a private channel, necessitating the use of the cloud connector.

AEP Certificate Inventory Behavior

By default, certificates enrolled through auto-enrollment protocols are placed in Monitored status in the CLM inventory. For new customers provisioned from the 2026.3.0 release onward, an instance-level flag (AEP_CERTS_DEFAULT_TO_MANAGED_STATUS) may be enabled, which causes all AEP-enrolled certificates to be placed directly into Managed status.

When this flag is enabled:
  • Certificates enrolled through any AEP protocol (EST, ACME, SCEP, CMP, MS Intune, WAEP) are placed in Managed status upon enrollment.
  • Certificates issued via AppViewX PKI (native CA) are placed in Managed status but are not counted toward CLM license consumption.
  • Certificates issued via third-party CAs continue to count toward CLM license consumption as applicable.
Existing customers are not affected by default. To enable this behavior for an existing instance, the SRE or TAC team must execute a DB script manually.