Opencrypt
Opencrypt is a managed PKI and trust platform built on OpenBao. It operates certificate authorities, issues and rotates certificates automatically, including through ACME, and distributes trust across environments, so teams get standardized certificate services without operating PKI infrastructure themselves.
Opencrypt standardizes enterprise certificate and trust lifecycle management on OpenBao, including protected Root CA governance, managed Intermediate CAs, automated certificate issuance and renewal through ACME or direct API calls, certificate revocation, PKI policy enforcement, trust bundle distribution, and auditable certificate operations. It integrates with cert-manager for Kubernetes workloads, so services in cluster environments get short lived, policy compliant certificates automatically. Application and platform teams consume PKI capabilities through declarative APIs and automated integrations rather than managing certificate authorities directly.
The operating challenge
Enterprise PKI becomes difficult to govern when certificate authorities, issuance policies, certificate renewal, revocation, trust distribution, and ownership are implemented independently across teams.
What Opencrypt provides
Opencrypt provides centrally governed Root and Intermediate CA services, automated certificate lifecycle management, reusable certificate profiles, trust distribution, monitoring, and auditable PKI operations, all backed by OpenBao.
How teams consume Opencrypt
Teams request certificates and PKI roles through declarative APIs, ACME, or automated integrations such as cert-manager, rather than standing up or operating a certificate authority themselves. Opencrypt handles issuance, rotation, revocation, and trust distribution behind the scenes, so services get short-lived, policy-compliant certificates without manual renewal.
How adoption starts
Define the enterprise trust hierarchy, establish Root and Intermediate CA governance, identify certificate profiles, onboard representative services to automated issuance and rotation, and progressively migrate existing certificate consumers.
Who it is for
Security and platform engineering teams that need consistent cryptographic controls, key-management patterns, and reusable trust capabilities across applications and workloads.
When not to use it
When application requirements are adequately covered by direct use of existing cloud key-management and cryptographic services without an additional platform abstraction.