OpenFrame Gen1 is Here · AI-driven, autonomous IT management. Out of beta and ready for production.

Identity and Access Management (IAM)

Full ACME protocol support including device-attestation challenges, letting standard ACME clients auto-enroll and renew certificates.
Issues short-lived SSH host and user certificates as a passwordless alternative to distributing static SSH keys.
Automates mutual TLS certificate issuance/rotation for service-to-service authentication in microservices and zero-trust architectures.
Defaults to short certificate lifetimes with automated renewal to reduce reliance on revocation.
step-issuer and step-cluster-issuer plug step-ca into cert-manager for native Kubernetes TLS issuance.
Supports JWK, OIDC/OAuth SSO, X5C, SSHPOP, SCEP, K8s Service Account, and AWS/GCP/Azure cloud-identity provisioners.
Apache 2.0 licensed with no feature gating on the core CA/CLI - usable in production at no cost.
Native ACME, SSH CA, and mTLS in one binary avoids stitching together separate tools.
First-class cert-manager issuer and cloud-identity provisioners suit containerized and multi-cloud environments.
Short-lived certs plus automated renewal reduce manual cert lifecycle work and outage risk from expired certs.
Backed by a funded company with extensive docs, tutorials, and a maintained GitHub repo.
Designing trust hierarchies, provisioners, and renewal policies demands real PKI/security knowledge.
Running step-ca in production HA (clustering, database backends, key storage/HSM) is on the operator.
The open-source CA is CLI/API-driven only; a graphical console is reserved for the paid Certificate Manager.
SSO for admin access, hosted multi-tenant management, and compliance attestations sit behind the paid product.
No public pricing for Certificate Manager, making cost comparison harder for smaller MSPs.
Be the first to share your experience with Smallstep.
Reduce costs and increase revenue with OpenFrame innovative open source solutions. Coming soon…
Learn More about OpenFrame