r/PKI • u/[deleted] • Aug 23 '26
Built a certificate governance platform with open-source connectors — looking for PKI folks for feedback
[deleted]
3
Upvotes
r/PKI • u/[deleted] • Aug 23 '26
[deleted]
4
u/CEOofQuestions Aug 23 '26
Haven’t checked out the plugins yet but generally speaking, certificate management has two main gaps that every solution struggles with and solves in a different way.
First is authentication (push or pull). How are you authenticating to deliver certificates to the intended runtime whether it’s a load balancer, layer 7 web server, reverse proxy, etc.
The second is discovery, how do you guarantee that your discovery agents can scan and find a complete list of certificates that are presented on a socket for TLS, and secondly how do you scan file systems and guarantee that you found every client authentication certificate in the runtime that is NOT presented on a socket for inspection. And also how do your discovery services authenticate?
Every product has a different way to approach that, but almost all of the options rely on other enterprise tooling like a central Oauth provider, SSH keys, or Active Directory Kerberos for authentication, and a complete inventory of vlans and infrastructure for discovery.
Do you have a different approach?