Ratings:
( ) ★ ★ ( ) ★ ★ ( ) ★ ★ ( ) ★ ★ ( ) ★ ★
(0)

Type:
Integration
Solutions:
Jamf for Mac , Jamf for Small Business , Jamf for Mobile
Products:
Jamf Pro
OS:
iOS , macOS , iPadOS , tvOS

Tags

BastionXP — Cloud PKI & ACME Certificate Manager

by Ampas Labs Inc.

Enterprise Grade Cloud PKI CA with ACME Certificate Manager

BastionXP is a cloud-native PKI CA and ACME server (with support for ACME Device Attestation) that integrates with Jamf to issue and renew device certificates automatically.

Unlike traditional cloud PKI or SCEP tools that require shared passwords, BastionXP verifies the device itself — using hardware attestation — before issuing a certificate, and replaces long-lived certs with short-lived ones that renew silently in the background. No shared secrets or passwords. BastionXP supports Apple Mobile Device Attestation natively.

If you're using a cloud PKI CA such as Entrust, SCEPman, EZCA, or a similar cloud CA with Jamf today, BastionXP is built to do that job — and add hardware-verified trust on top. It scales from a handful of devices to fleets of 100,000+ certificates, so it fits small businesses and large enterprises alike.

Why it matters

Most PKI tools solve certificate distribution. They don't solve trust — proving a certificate request really comes from your managed device, not a stolen shared secret or password. Long-lived certificates (1–2 years) also leave a wide window of exposure if a device is lost or compromised.  

BastionXP closes both gaps by supporting ACME Device Attestation Protocol and issuing short-lived certificates that are valid for a day or few hours.

Key features

  • Hardware-rooted attestation — verifies device identity via Apple's Secure Enclave before issuing any certificate.  Supports Apple Mobile Device Attestation.
  • Short-lived, auto-renewing certs — hours, not years, renewed automatically via ACME
  • ACME-based, RFC 8555 compliant — a modern replacement for legacy SCEP, no proprietary agents
  • Real-time revocation — mark a device "Stolen" in Jamf and BastionXP stops issuing it certificates instantly
  • Zero-touch enrollment — new devices are provisioned automatically on first connect
  • SSO/IAM ready — works with Google Workspace, Microsoft 365, Okta, Keycloak, AWS IAM, plus RBAC
  • Secures more than certs — Wi-Fi, VPN, SaaS access, and a built-in SSH proxy/bastion host
  • Deploy anywhere — self-hosted or SaaS, on AWS, GCP, Azure, or DigitalOcean
  • Scales with you — from a handful of devices at a small business or startup to 100,000+ certificates at large enterprises

Who it's for

  • IT/Jamf admins replacing or upgrading a cloud PKI setup
  • Security teams looking to shrink certificate-based attack surface and replace legacy SCEP
  • DevOps teams wanting automated ACME based certificate issuance
  • End users — zero setup, nothing to remember, it just works automatically

Enterprise Grade Cloud PKI CA with ACME Certificate Manager

BastionXP Cloud PKI CA With ACME Device Attestation.