Private PKI

Your own CA,
production-ready and audit-proof.

mTLS between microservices, device identities in the field, internal code-signing roots: NextPKI delivers a Private CA with HSM backing, rotation and audit, as a service or on-prem.

mTLS · IoT · workload identity · code signingHSM-backed · YubiHSM · CloudHSM · NitrokeyHours to 10-year roots
Root CAOffline · HSMIssuing CATLSIssuing CAIdentityTLSmTLSS/MIMECodesrv-01TLS · 90dusr-08S/MIME · 1yiot-44mTLS · 30dsvc-12Code · 1ysrv-02TLS · 90d+ Zertifikat ausstellen
Use cases mTLS · IoT · workload identity · code signing
Keys HSM-backed · YubiHSM · CloudHSM · Nitrokey
Lifecycle Hours to 10-year roots
Crypto ECDSA · Ed25519 · ML-DSA-ready
Why a Private PKI

Trust you control yourself.

Where public CAs don't fit, because devices are offline, rotation is too fast, or compliance demands it.

01

Service mesh & mTLS

Short-lived worker certificates for Istio, Linkerd, Consul Connect or your own gRPC stacks. Rotation every few hours, transparent to workloads.

02

IoT device identities

Provisioning hooks for manufacturing, in-field renewal, revocation lists with OCSP stapling, even for devices with minimal connectivity.

03

Internal S/MIME

Each employee gets a per-device S/MIME identity, derived from your IdP, no CSV upload at a public CA.

04

Code & container signing

Signatures for internal build pipelines, container images, firmware. Fully auditable, with time-stamping.

05

HSM or software keys

Root and issuing keys in YubiHSM, CloudHSM or Nitrokey HSM 2. Software fallback only in dev environments.

06

Migration from AD CS

Run your existing Microsoft PKI as a bridge, lift it to NextPKI step by step, no big bang.

Architecture understood in an hour

Cleanly separated layers, nothing hidden.

We don't make a magic layer out of PKI. Four clean building blocks that pass any audit.

01
Root Offline, HSM-backed

Lives 10-20 years. Never leaves the HSM. Only activated for issuing-CA rotations.

02
Issuing Online, short-lived

One issuing CA per workload class. Rotates yearly, online for the renewal API.

03
Workload Short-lived certificates

Hours to days. Renewed automatically over ACME or workload-identity tokens (SPIFFE-compatible).

04
Audit Append-only log

Every issuance, every revocation, every policy change, signed and tamper-resistant.

Plan your Private PKI

A trust hierarchy you control for the long term.

We set up your Private PKI with you, with a clean handover to your team. Cloud service or on-prem. You decide.