Coming soonGoReactApache 2.0

Guard your cryptographic trust.

KryptKeeper is an open-source PKI and certificate lifecycle platform. It runs your certificate authorities, finds every certificate in your estate, including ones it never issued, and shows a person exactly what needs them today.

kryptkeeper · What needs a human
KryptKeeper overview: a 90-day certificate expiry chart and tiles for 247 certificates, 18 expiring in 30 days, 3 expired, 84 endpoints discovered and 12 risky
Demo data. The overview leads with what needs a person, not with charts.
The problem

Certificates fail quietly, then all at once.

Most organizations hold certificates from DigiCert, Sectigo, Let's Encrypt, Active Directory Certificate Services and a few forgotten issuers from old acquisitions. Nobody has the full list, so the first sign of trouble is an outage when one expires.

KryptKeeper starts with visibility. Every certificate it knows about gets an origin (issued here, imported, discovered or synced) and a management state: managed, external, or unmanaged, which is the risk column. From any unmanaged row, one flow assigns an owner and a path to manage it.

What it does

Three jobs, one platform

See

Inventory everything

Network discovery scanning, agentless SSH and WinRM, CT-log monitoring, bulk import of PEM, PKCS#7 and CSV, and sync from ADCS.

Manage

Run the full lifecycle

Root and issuing CAs, templates, approvals, renewal autopilot, bulk revoke and re-issue, and key rotation with passphrase-wrapped backups.

Prove

Answer the auditor

An append-only audit log, SOC 2 and PCI DSS evidence packs, CA health, expiry timelines and an algorithm-sunset report for post-2030 compliance.

How it works

A single Go binary

The CA engine, the API and every protocol endpoint run in one binary. The dashboard is a compiled React app. Signing always goes through Go's crypto.Signer, so swapping key storage never touches CA logic.

Specs

Built for real PKI work

Enrollment protocols
ProtocolRFCUsed for
ACME8555Web server TLS with certbot or acme.sh
EST7030Enterprise device enrollment
SCEPn/aNetwork devices: F5, Citrix, Palo Alto
OCSP5019Real-time revocation checks
CRL5280Revocation lists
CMP4210Certificate Management Protocol
MS-XCEP / MS-WSTEPn/aWindows auto-enrollment, replacing ADCS
vs step-ca and EJBCA
  • OCSP responder included in open source
  • Built-in discovery: network, agentless, CT logs
  • First open-source ADCS replacement
  • Post-quantum ready with ML-DSA (FIPS 204)
Tested against real systems
13live interop scenarios passing
36Go packages under test
202dashboard tests
Deploy

Docker Compose for a single node, a Helm chart for Kubernetes, or the plain binary. TLS on by default, and it refuses to start on missing secrets.

Status

Where it is now

  1. v1.0 to v2.2Full CA engine and protocols, compliance reports, renewal autopilot, PQC copilot, MCP operations, SPIFFE
  2. NowEstate management: CA-agnostic inventory, ADCS sync and the takeover flow for unmanaged certificates
  3. NextSSH certificate authority with short-lived certs, and commercial CA connectors

Launching soon at kryptkeeper.io

Apache 2.0. The core CA, every protocol server, discovery and the dashboard stay free.

Visit kryptkeeper.io