Skip to content

hungmhdo/baseca

 
 

Repository files navigation

coinbase/baseca

Go Report Card PR Build Release Build

Overview

baseca is a gRPC service that serves as a Public Key Infrastructure (PKI) control plane intended to provide a safe and scalable approach to issue short-lived end-entities certificates.

Use Cases

baseca extends the pathlen constraint from AWS Private CA and acts as an Intermediate CA; instead of issuing leaf certificates directly from Private CA, baseca manages many Subordinate CAs and signs requests in-memory depending on the scope of the service account.

  • Client Authentication
  • Server Authentication
  • Code Signing
  • SSH Certificates (Pending)

Running baseca

Benefits

  • Short-Lived Certificates with Ephemeral Private Key Material
  • No Quotas on Quantity of Issued Certificates
  • Supports Issuance from On-Prem and Multi-Cloud
  • Protects Issuance of Certificates on Scope
  • Supports Node Attestation
  • Cost Savings

About

No description, website, or topics provided.

Resources

License

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Go 88.9%
  • HCL 9.9%
  • Other 1.2%