Skip to content

certificates

Network Security

A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.

Go Latest v0.30.2 · 4mo ago Security brief →

Features

  • Fast, stable private certificate authority (CA) supporting RSA, ECDSA, EdDSA keys
  • Automates short‑lived certificate issuance, renewal and passive revocation
  • Multiple database backends (Badger, BoltDB, PostgreSQL, MySQL)
  • Provides a private ACME server with common challenge types for automated TLS certs
  • Supports diverse authentication provisioners (OAuth OIDC tokens, cloud instance IDs, JWK tokens, X5C certificates, etc.)

Recent releases

View all 3 releases →
v0.30.2 Maintenance

Updated gRPC dependency to v1.79.3 for compatibility and stability improvements.

v0.30.1 Maintenance

Released multiple platform builds (Linux, macOS, Windows) with sigstore/cosign signing verification and checksums for cryptographic security assurance.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
8,669
Forks
567
Languages
Go Shell Makefile

Community & Support

Alternative to

Smallstep Certificate Manager

Beta — feedback welcome: [email protected]