7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

2 alternatives ranked by real activity

Open-source Entrust alternatives

A curated, ranked list of the 2 best open-source alternatives to Entrust.

The best open-source alternative to Entrust is step-ca. If that doesn't suit you, another good option is privacyIDEA.

Entrust alternatives are mainly security tools, but some are also auth & identity tools. 2 of them shipped code in the last 30 days, 2 can be self-hosted, and 1 uses a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

step-ca

step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows.

GitHub stars
8.9k
Last commit
3 days ago
Latest release
v0.30.2
Licence
Apache-2.0
Self-hosted
Yes
smallstep.comstep-ca homepage screenshot

step-ca, published as smallstep/certificates, is an online private certificate authority built for automated certificate management in DevOps environments. It is the server counterpart to the step command-line tool, and both are maintained by Smallstep Labs.

It can issue HTTPS server and client certificates trusted by browsers, as well as TLS certificates for virtual machines, containers, APIs, database connections and Kubernetes pods. It also issues SSH certificates: users can obtain them with single sign-on tokens, and hosts can obtain them using cloud instance identity documents. As an ACME server it supports the popular challenge types, and a Go wrapper and the step CLI help with scripting.

step-ca is written in Go and released under Apache-2.0. It is tuned for a two-tier PKI, and the README points teams that need multiple authorities, active revocation through CRL or OCSP, device attestation or a web admin UI to Smallstep's separate commercial product.

Key features

  • Private certificate authority for X.509
  • SSH certificates for users and hosts
  • ACME server with common challenge types
  • TLS certificates for containers and Kubernetes pods
  • Single sign-on token exchange for SSH access
  • Go wrapper and step CLI automation

Pricing: Open source under Apache-2.0; Smallstep also sells a separate commercial CA product with additional features.

privacyIDEA

An open-source authentication server for managing two-factor and multi-factor logins with OTP tokens, push, FIDO2 keys and passkeys across an organization.

GitHub stars
1.8k
Last commit
today
Latest release
v3.14
Licence
AGPL-3.0
Self-hosted
Yes
privacyidea.orgprivacyIDEA homepage screenshot

privacyIDEA is an open-source authentication server that manages multi-factor authentication for an organization. It issues and verifies second factors such as one-time passwords, hardware tokens, push notifications and FIDO2 or WebAuthn security keys, so applications and servers can add two-factor login without each building its own token handling.

The server is written in Python and exposes an API that other systems can call to check a login attempt. Its topics point to support for OTP, passkeys, push authentication and certificates, and administrators enroll and manage tokens centrally rather than configuring every service by hand. The project documentation includes how-tos for running it behind Apache2 with MySQL and for protecting a whole server farm.

privacyIDEA is released under the AGPL-3.0 licence and can be self-hosted, which keeps token data and user policies on infrastructure you control. The project website also lists an Enterprise Edition next to the community version, along with a demo site, screenshots and community resources for anyone evaluating it.

Key features

  • OTP, push, and hardware token support
  • FIDO2, WebAuthn, and passkey authentication
  • REST API for application integration
  • Central web interface for token enrollment
  • Policy-based control of authentication rules
  • Certificate and CA related features

Pricing: The community edition is free and open source under AGPL-3.0; an Enterprise Edition is also listed on the project website.

Entrust alternatives: questions

What is the best open-source alternative to Entrust?
step-ca is the top-ranked open-source alternative to Entrust on Enlisted: step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows. Another strong option is privacyIDEA.
Are these Entrust alternatives free?
Both are open source, so the code is free to use under its licence, and both can be self-hosted on your own server or computer.
How is this list of Entrust alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 2 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all