XiPKI

C
C tier on Public Key Infrastructure SoftwareScore 6.9 · #4 of 25
Android app
Not listed
Free plan
Yes
Runs on
api, Linux, Mac, self-hosted
github.com
The XiPKI homepage

Summary

XiPKI is an open-source public key infrastructure system for certification authority, registration authority, and OCSP responder functions, intended for critical infrastructure. It can manage multiple CAs in one software instance, support database clusters and active instances for the same CA, and offers CA administration through embedded OSGi commands and an API. Its protocol gateway supports EST, SCEP, CMP, ACME, and XiPKI's RESTful API. The OCSP responder supports several standards and request types, health checks, and multiple certificate status sources. HSM connections use PKCS#11, with devices from AWS CloudHSM, Nitrokey, nCipher, Sansec, SoftHSM, TASS, Thales, and Utimaco listed. The project describes native support for ML-DSA, ML-KEM, and composite post-quantum algorithms. XiPKI supports Linux and macOS, requires Java 11 or later and Tomcat 10 or 11, and lists DB2, MariaDB, MySQL, Oracle, PostgreSQL, H2, and HSQLDB as supported databases. It is free under Apache License 2.0. Setup archives are available from GitHub Releases or Maven Central, and the software can also be built from source.

Who it is for

XiPKI is aimed at organizations that need CA, RA, or OCSP responder capabilities, including critical infrastructure. It may suit teams able to operate supported Linux or macOS environments and meet its Java and Tomcat requirements.

What is good

  • Free and open source under Apache License 2.0.
  • Supports EST, SCEP, CMP, ACME, and its RESTful API.
  • Connects to HSMs through PKCS#11.
  • Supports multiple CAs in one instance.
  • Lists native post-quantum algorithm support.

What to know first

  • Requires Java 11 or later and Tomcat 10 or 11.
  • Supported operating systems are Linux and macOS.
  • Setup may require building from source or using an archive.

Verdict

XiPKI covers CA management, certificate protocols, HSM connections, and OCSP responder functions in a free, self-hosted system. Check its operating requirements and supported databases against your environment before deployment.

XiPKI plans and pricing

All plans
Apache License 2.0 Free Open-source software under Apache Software License, Version 2.0 github.com · 4 Oct 2026

Compared on public key infrastructure software

Deployment model
on_premisesgithub.com
ACME support
Yesgithub.com
SCEP support
Yesgithub.com
EST support
Yesgithub.com
HSM integration
Yesgithub.com
Certificate profiles
Yesgithub.com

Facts

Purpose
XiPKI is an open-source public key infrastructure system covering certification authority, registration authority, and OCSP responder functions, intended for critical infrastructure.github.com · 4 Oct 2026
Post-quantum cryptography
The project describes native support for ML-DSA, ML-KEM, and composite post-quantum algorithms.github.com · 4 Oct 2026
Certificate protocols
Its CA protocol gateway supports EST, SCEP, CMP, ACME, and XiPKI's own RESTful API.github.com · 4 Oct 2026
HSM integrations
It supports HSM integration through PKCS#11 and lists AWS CloudHSM, Nitrokey, nCipher, Sansec, SoftHSM, TASS, Thales, and Utimaco devices.github.com · 4 Oct 2026
Operating requirements
The project lists Linux and macOS, Java 11 or later, and Tomcat 10 or 11 as supported platform requirements.github.com · 4 Oct 2026
Database support
Supported databases listed are DB2, MariaDB, MySQL, Oracle, PostgreSQL, H2, and HSQLDB.github.com · 4 Oct 2026
CA management
XiPKI supports multiple CAs in one software instance, database clusters, active instances for the same CA, and CA management through embedded OSGi commands and an API.github.com · 4 Oct 2026
OCSP
The OCSP responder supports RFC 2560 and RFC 6960, the lightweight high-volume profile in RFC 5019, signed and unsigned requests, health checks, and several certificate status sources including EJBCA databases.github.com · 4 Oct 2026
Security and compliance
The project says Bouncy Castle can be switched between LTS and FIPS variants to meet different compliance requirements, and lists eIDAS standards EN 319 411 and EN 319 412 support.github.com · 4 Oct 2026
Downloads
The setup archive can be downloaded from GitHub Releases or Maven Central, or built from source.github.com · 4 Oct 2026
Support
The project directs users to open a GitHub issue and asks bug reports to include test data, logs, version, OS, JRE or JDK, and reproduction steps.github.com · 4 Oct 2026
Latest release
The releases page lists v6.7.1 as the latest release, dated 2026/09/07.github.com · 4 Oct 2026
Maker
The GitHub account identifies the project author as Lijun Liao, PhD, and lists Germany as the location.github.com · 4 Oct 2026

Best XiPKI alternatives

See all 20

Where it ranks on Everything Xiaomi

Is XiPKI yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources