XiPKI
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted

Summary
XiPKI is an open-source public key infrastructure system for certification authority, registration authority, and OCSP responder functions, intended for critical infrastructure. It can manage multiple CAs in one software instance, support database clusters and active instances for the same CA, and offers CA administration through embedded OSGi commands and an API. Its protocol gateway supports EST, SCEP, CMP, ACME, and XiPKI's RESTful API. The OCSP responder supports several standards and request types, health checks, and multiple certificate status sources. HSM connections use PKCS#11, with devices from AWS CloudHSM, Nitrokey, nCipher, Sansec, SoftHSM, TASS, Thales, and Utimaco listed. The project describes native support for ML-DSA, ML-KEM, and composite post-quantum algorithms. XiPKI supports Linux and macOS, requires Java 11 or later and Tomcat 10 or 11, and lists DB2, MariaDB, MySQL, Oracle, PostgreSQL, H2, and HSQLDB as supported databases. It is free under Apache License 2.0. Setup archives are available from GitHub Releases or Maven Central, and the software can also be built from source.
Who it is for
XiPKI is aimed at organizations that need CA, RA, or OCSP responder capabilities, including critical infrastructure. It may suit teams able to operate supported Linux or macOS environments and meet its Java and Tomcat requirements.
What is good
- Free and open source under Apache License 2.0.
- Supports EST, SCEP, CMP, ACME, and its RESTful API.
- Connects to HSMs through PKCS#11.
- Supports multiple CAs in one instance.
- Lists native post-quantum algorithm support.
What to know first
- Requires Java 11 or later and Tomcat 10 or 11.
- Supported operating systems are Linux and macOS.
- Setup may require building from source or using an archive.
Verdict
XiPKI covers CA management, certificate protocols, HSM connections, and OCSP responder functions in a free, self-hosted system. Check its operating requirements and supported databases against your environment before deployment.
XiPKI plans and pricing
All plansCompared on public key infrastructure software
- Deployment model
- on_premisesgithub.com
- ACME support
- Yesgithub.com
- SCEP support
- Yesgithub.com
- EST support
- Yesgithub.com
- HSM integration
- Yesgithub.com
- Certificate profiles
- Yesgithub.com
Facts
- Purpose
- XiPKI is an open-source public key infrastructure system covering certification authority, registration authority, and OCSP responder functions, intended for critical infrastructure.github.com · 4 Oct 2026
- Post-quantum cryptography
- The project describes native support for ML-DSA, ML-KEM, and composite post-quantum algorithms.github.com · 4 Oct 2026
- Certificate protocols
- Its CA protocol gateway supports EST, SCEP, CMP, ACME, and XiPKI's own RESTful API.github.com · 4 Oct 2026
- HSM integrations
- It supports HSM integration through PKCS#11 and lists AWS CloudHSM, Nitrokey, nCipher, Sansec, SoftHSM, TASS, Thales, and Utimaco devices.github.com · 4 Oct 2026
- Operating requirements
- The project lists Linux and macOS, Java 11 or later, and Tomcat 10 or 11 as supported platform requirements.github.com · 4 Oct 2026
- Database support
- Supported databases listed are DB2, MariaDB, MySQL, Oracle, PostgreSQL, H2, and HSQLDB.github.com · 4 Oct 2026
- CA management
- XiPKI supports multiple CAs in one software instance, database clusters, active instances for the same CA, and CA management through embedded OSGi commands and an API.github.com · 4 Oct 2026
- OCSP
- The OCSP responder supports RFC 2560 and RFC 6960, the lightweight high-volume profile in RFC 5019, signed and unsigned requests, health checks, and several certificate status sources including EJBCA databases.github.com · 4 Oct 2026
- Security and compliance
- The project says Bouncy Castle can be switched between LTS and FIPS variants to meet different compliance requirements, and lists eIDAS standards EN 319 411 and EN 319 412 support.github.com · 4 Oct 2026
- Downloads
- The setup archive can be downloaded from GitHub Releases or Maven Central, or built from source.github.com · 4 Oct 2026
- Support
- The project directs users to open a GitHub issue and asks bug reports to include test data, logs, version, OS, JRE or JDK, and reproduction steps.github.com · 4 Oct 2026
- Latest release
- The releases page lists v6.7.1 as the latest release, dated 2026/09/07.github.com · 4 Oct 2026
- Maker
- The GitHub account identifies the project author as Lijun Liao, PhD, and lists Germany as the location.github.com · 4 Oct 2026
Best XiPKI alternatives
See all 20Where it ranks on Everything Xiaomi
Is XiPKI yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/xipki/xipki· checked 4 Oct 2026
- github.com/xipki/xipki/releases· checked 4 Oct 2026
- github.com/xipki· checked 4 Oct 2026