6,598 open-source and SaaS tools, with GitHub stats refreshed every day.

4 alternatives ranked by real activity

Open-source Keyfactor alternatives

A curated, ranked list of the 4 best open-source alternatives to Keyfactor.

The best open-source alternative to Keyfactor is cert-manager. If that doesn't suit you, other good options are Certimate, step-ca and OpenBao.

Keyfactor alternatives are mainly Security tools, but some are also Infrastructure & Containers. 4 of them shipped code in the last 30 days, 4 can be self-hosted, and 4 use a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

cert-manager

Kubernetes add-on that issues and renews TLS certificates automatically from sources such as Let's Encrypt and HashiCorp Vault.

GitHub stars
14k
Last commit
today
Latest release
v1.21.2
Licence
Apache-2.0
Self-hosted
Yes
cert-manager.iocert-manager homepage screenshot

cert-manager is an open-source Kubernetes add-on that treats certificates and certificate issuers as native cluster resources. Instead of requesting, installing and renewing TLS certificates by hand, operators declare what they need and the controller obtains and maintains it, which reduces the chance of an outage caused by an expired certificate.

It can issue certificates from several sources, including Let's Encrypt through ACME, HashiCorp Vault and CyberArk Certificate Manager, as well as from an issuer running inside the cluster itself. It also watches expiry dates and attempts renewal at a suitable time before a certificate lapses. A common use is securing Ingress resources automatically.

The project is written in Go and released under the Apache-2.0 license. It runs inside your own cluster, with several installation methods documented on cert-manager.io, plus a getting started guide and a quick start for nginx-ingress. Community help is available through the Kubernetes Slack channels and the issue tracker.

Key features

  • Certificates and issuers as Kubernetes resources
  • Issuance from Let's Encrypt via ACME
  • HashiCorp Vault and CyberArk issuer support
  • Automatic renewal before certificates expire
  • Automatic TLS for Ingress resources
  • Local in-cluster certificate issuance

Pricing: Free and open source under the Apache-2.0 license.

Certimate

A self-hosted ACME tool with a visual workflow that automates issuing, deploying, renewing and monitoring SSL/TLS certificates across many DNS and cloud providers.

GitHub stars
9.3k
Last commit
5 days ago
Latest release
v0.4.34
Licence
MIT
Self-hosted
Yes
docs.certimate.meCertimate homepage screenshot

Certimate is an open-source, free, self-hosted tool for managing SSL certificates through the ACME protocol. It automates the full lifecycle, from issuing a certificate to deploying it, renewing it and watching its status, using a visual workflow instead of hand-written scripts.

It can request single-domain, multi-domain and wildcard certificates as well as IP address certificates, in RSA or ECC, using DNS-01 or HTTP-01 challenges, and export them as PEM, PFX or JKS. It supports more than 70 domain providers, such as AWS, Cloudflare, GoDaddy, Alibaba Cloud and Tencent Cloud, and more than 160 deployment targets including Kubernetes, CDNs, WAFs and load balancers. ACME authorities include Let's Encrypt, Google Trust Services, ZeroSSL, SSL.com and Actalis, and notifications can go to email, Discord, Slack, Telegram, DingTalk, Feishu and WeCom.

Certimate is a single Go program with no database or runtime to install, uses little memory, and runs on Windows, Linux and macOS, either as a downloaded binary or in Docker. All data is stored locally. It is MIT licensed and suits administrators who manage many certificates across providers.

Key features

  • Visual workflows for certificate lifecycle
  • Wildcard, multi-domain and IP certificates
  • DNS-01 and HTTP-01 challenges
  • PEM, PFX and JKS formats
  • 70+ DNS providers and 160+ deployment targets
  • Multiple ACME certificate authorities
  • Notifications by email, Slack, Discord and more
  • Single binary or Docker install

Pricing: Free and open source under the MIT licence.

step-ca

step-ca from Smallstep is an open-source private certificate authority and ACME server that issues X.509 and SSH certificates for automated DevOps workflows.

GitHub stars
8.9k
Last commit
3 days ago
Latest release
v0.30.2
Licence
Apache-2.0
Self-hosted
Yes
smallstep.comstep-ca homepage screenshot

step-ca, published as smallstep/certificates, is an online private certificate authority built for automated certificate management in DevOps environments. It is the server counterpart to the step command-line tool, and both are maintained by Smallstep Labs.

It can issue HTTPS server and client certificates trusted by browsers, as well as TLS certificates for virtual machines, containers, APIs, database connections and Kubernetes pods. It also issues SSH certificates: users can obtain them with single sign-on tokens, and hosts can obtain them using cloud instance identity documents. As an ACME server it supports the popular challenge types, and a Go wrapper and the step CLI help with scripting.

step-ca is written in Go and released under Apache-2.0. It is tuned for a two-tier PKI, and the README points teams that need multiple authorities, active revocation through CRL or OCSP, device attestation or a web admin UI to Smallstep's separate commercial product.

Key features

  • Private certificate authority for X.509
  • SSH certificates for users and hosts
  • ACME server with common challenge types
  • TLS certificates for containers and Kubernetes pods
  • Single sign-on token exchange for SSH access
  • Go wrapper and step CLI automation

Pricing: Open source under Apache-2.0; Smallstep also sells a separate commercial CA product with additional features.

OpenBao

OpenBao is an open-source, community-governed secrets manager that stores, encrypts and distributes secrets, certificates and keys for modern infrastructure.

GitHub stars
8.3k
Last commit
today
Latest release
v2.7.1
Licence
MPL-2.0
Self-hosted
Yes
openbao.orgOpenBao homepage screenshot

OpenBao is a software solution for managing, storing and distributing sensitive data such as secrets, certificates and keys. It is a community-led project, run under open-governance principles, that intends to stay available under an OSI-approved open-source licence, currently MPL-2.0.

The README describes the problem it targets: modern systems need many secrets, including database credentials, API keys for external services and credentials for service-to-service communication, and tracking who accesses what is hard without a dedicated tool. OpenBao encrypts key/value secrets before they reach persistent storage, so access to the raw storage alone does not expose them. It can write to disk, PostgreSQL and other backends, and it can generate dynamic secrets on demand for systems such as AWS or SQL databases.

OpenBao is written in Go and is widely known as a fork of HashiCorp Vault, which makes it a candidate for teams looking for an open-governance alternative in that space. It runs on your own infrastructure, and the project coordinates through a mailing list, GitHub Discussions and chat channels, with working groups for areas such as namespaces and the UI.

Key features

  • Encrypted key/value secret storage
  • Dynamic secrets for AWS and SQL databases
  • Multiple storage backends including PostgreSQL
  • Certificate and key management
  • Audit logging of secret access
  • Open-governance community project

Pricing: Free and open source under the MPL-2.0 licence.

Keyfactor alternatives: questions

What is the best open-source alternative to Keyfactor?
cert-manager is the top-ranked open-source alternative to Keyfactor on Enlisted: Kubernetes add-on that issues and renews TLS certificates automatically from sources such as Let's Encrypt and HashiCorp Vault. Other strong options are Certimate, step-ca and OpenBao.
Are these Keyfactor alternatives free?
All 4 are open source, so the code is free to use under its licence, and 4 of them can be self-hosted on your own server.
How is this list of Keyfactor alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 4 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all