VaulTLS
Network SecurityA modern web‑based platform for managing mTLS and SSH X.509 certificates, with automated generation, distribution, expiration alerts, OIDC auth, API access, and container deployment.
Features
- Comprehensive TLS (X.509) certificate management
- SSH certificate management
- Modern web UI for full certificate lifecycle control
- OpenID Connect authentication and email expiration notifications
- RESTful API for automation
Recent releases
View all 7 releases →
v1.1.1
Bugfix
Fixes mismatch between OpenSSL and rcgen in Certificate Revocation List identifier generation.
v1.1.0
Security relevant
Security fixes
- Vite vulnerability fix
- picomatch vulnerability fix
- yaml vulnerability fix
Notable features
- PEM-format CRL download option
- Password reset environment variables (VAULTLS_ACCOUNT_EMAIL, VAULTLS_ACCOUNT_PASSWORD)
- RFC 5280 TLS certificate extensions (SKI, AKI) for mTLS compliance
v1.0.1
New feature
Breaking changes
- Delete operation now requires revoke first
Security fixes
- Critical settings parsing bug fix
- Security bug fixes
Notable features
- Certificate Revocation Lists
- Dark theme UI
- Revoke before delete workflow
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Install via
docker