Opencrypt

Opencrypt is a managed PKI and trust platform built on OpenBao. It operates certificate authorities, issues and rotates certificates automatically, including through ACME, and distributes trust across environments, so teams get standardized certificate services without operating PKI infrastructure themselves.

Abstract system diagram for Opencrypt
Type

Reusable security platform capability

Deployment

Integrated into the customer's application and runtime environments alongside existing identity, key management, HSM, cloud security, and platform services.

Ownership

Customer controlled trust boundaries, keys, and policies, with Infer Origins implementation and integration.

Opencrypt standardizes enterprise certificate and trust lifecycle management on OpenBao, including protected Root CA governance, managed Intermediate CAs, automated certificate issuance and renewal through ACME or direct API calls, certificate revocation, PKI policy enforcement, trust bundle distribution, and auditable certificate operations. It integrates with cert-manager for Kubernetes workloads, so services in cluster environments get short lived, policy compliant certificates automatically. Application and platform teams consume PKI capabilities through declarative APIs and automated integrations rather than managing certificate authorities directly.

The operating challenge

Enterprise PKI becomes difficult to govern when certificate authorities, issuance policies, certificate renewal, revocation, trust distribution, and ownership are implemented independently across teams.

What Opencrypt provides

Opencrypt provides centrally governed Root and Intermediate CA services, automated certificate lifecycle management, reusable certificate profiles, trust distribution, monitoring, and auditable PKI operations, all backed by OpenBao.

How teams consume Opencrypt

Teams request certificates and PKI roles through declarative APIs, ACME, or automated integrations such as cert-manager, rather than standing up or operating a certificate authority themselves. Opencrypt handles issuance, rotation, revocation, and trust distribution behind the scenes, so services get short-lived, policy-compliant certificates without manual renewal.

How adoption starts

Define the enterprise trust hierarchy, establish Root and Intermediate CA governance, identify certificate profiles, onboard representative services to automated issuance and rotation, and progressively migrate existing certificate consumers.

Who it is for

Security and platform engineering teams that need consistent cryptographic controls, key-management patterns, and reusable trust capabilities across applications and workloads.

When not to use it

When application requirements are adequately covered by direct use of existing cloud key-management and cryptographic services without an additional platform abstraction.

Designed outcomes

Centralized enterprise trust management
Reduced certificate operational overhead
Fewer expiry related outages through automated lifecycle management
Consistent PKI security controls across environments
Automated, policy compliant certificates for Kubernetes workloads
Product engagement

Start with one valuable workload.

Book an architecture session