Version 0.2.0-alpha — single-node CA, ACME issuance, and cert templates are working; federation not started
To update an existing install:
git pull origin main && sudo ./update.sh
An opinionated, open-source ACME PKI platform built on step-ca.
ForgedCA aims to be the easiest way to stand up a production-grade private PKI on-prem. The bar we're building against: a non-PKI-expert admin can stand up a working multi-tier CA and distribute trust to their fleet in under an hour.
Made by ForgedIO.
Alpha — single-node PKI works end to end. Install, log in, enroll MFA, run the wizard, and you have a working Root → Intermediate → Issuing chain issuing certs over ACME. Not production-ready: no revocation UI, no audit log, no email or external IdPs, and federation is still ahead of us.
Working today
- Install wizard — pick Root / Intermediate / Issuing (any combination) and bootstrap the full chain on one box
- Forced password change plus TOTP MFA enrollment with recovery codes on first login
- The wizard issues the admin UI's own leaf cert and swaps nginx onto it, so installing the Root turns the lock green on this very UI
- Trust-chain and per-cert PEM download, with an inline viewer and copy button on every pane
- step-ca daemon lifecycle from Settings — start / stop / status with an in-UI log tail
- ACME provisioners, managed from the UI and written straight into step-ca's
ca.json - ACME client onboarding page with ready-to-paste snippets for
step,certbot,acme.sh, cert-manager, Traefik, Caddy, and nginx - Certificate templates — CRUD, per-provisioner binding, lifetime bounds, and an EKU / Key Usage policy that step-ca enforces on every issued cert
- Light / dark theme
Not built yet: SCEP, manual CSR signing, trust-store distribution kits (GPO / Intune / .mobileconfig), DNS-01, dashboard rollups, revocation UI, audit log, email, syslog, external IdPs, and all federation.
See docs/roadmap.md for the full slice sequence and docs/CHANGELOG.md for per-release detail.
- Web-based install wizard — pick whether a server is a Root CA, Intermediate CA, Issuing CA, or any combination
- ACME issuance with HTTP-01 and (where feasible) DNS-01 validation
- Federation — any server deployed as Intermediate or Issuing can point back at the Root to auto-enroll
- Fleet-wide management — logging into any node shows a live dashboard of the entire PKI (live-queried from peers)
- Trust-store deployment helpers — one-click GPO ADMX, Intune profiles, and ready-to-paste snippets for cert-manager, Traefik, Caddy, nginx, certbot, acme.sh
- Flexible lifetimes — long-lived CA certs, short-lived ACME leaves, non-ACME templates bounded by the issuer's remaining lifetime
- Offline Root CA support — USB sneakernet ceremony for orgs that require an air-gapped Root
- Revocation + OCSP that an admin can operate without reading a whitepaper
- MFA mandatory on first admin login — TOTP for local / LDAP / generic OIDC / SAML users; skipped for Entra ID and Duo-layered logins where the IdP provides MFA
- IdPs in v1: Local, LDAP, Entra ID, Generic SAML 2.0, Generic OIDC, and Duo as a layered MFA provider
- Email via SMTP or Microsoft Graph API; syslog forwarding required
- A dedicated Linux server (not the Proxmox host if using Proxmox; not a shared appliance)
- Python 3.10+ (installed automatically by
install.sh) - PostgreSQL 13+ (installed automatically by
install.sh) - Root/sudo access for the installer
- Network reachability between nodes if deploying multi-tier federation (except for offline Root, which uses USB sneakernet)
| Family | Tested distros |
|---|---|
| Debian / Ubuntu | Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Debian 11, Debian 12 |
| RHEL / CentOS Stream / Rocky | CentOS Stream 9, CentOS Stream 10, Rocky Linux 8/9, AlmaLinux 8/9, RHEL 8/9 |
| SUSE / openSUSE | openSUSE Leap 15, openSUSE Tumbleweed |
The installer auto-detects apt, dnf, yum, or zypper and installs the correct packages for your distribution.
SELinux note (RHEL/CentOS/Rocky): The installer applies the required policy automatically — httpd_can_network_connect, HTTPS port labelling, and restorecon on the app directory.
- Creates
forgedcaandstep-casystem users and groups - Writes application files to
/opt/forgedca/and step-ca state to/etc/step-ca/+/var/lib/step-ca/ - Installs system packages (Postgres, nginx, step-ca, Python deps)
- Writes systemd unit files to
/etc/systemd/system/ - Configures nginx, including a sudoers rule so the
forgedcaservice user can reload nginx without a password - Generates a self-signed TLS certificate for the web UI
uninstall.sh also requires root.
git clone https://github.com/ForgedIO/forged-ca.git
cd forged-ca
sudo ./install.shCustom HTTPS port:
sudo ./install.sh --port 9443The installer:
- Creates the
forgedcaandstep-casystem users - Installs Python, Postgres, Redis, nginx, Node/npm, and step-ca
- Creates a Python virtualenv and installs dependencies
- Bootstraps two Postgres databases:
forgedca(app state) andstep_ca(step-ca's own state) - Generates a self-signed TLS certificate for the web UI
- Configures nginx as a reverse proxy
- Installs systemd units for Gunicorn and Celery (step-ca's unit is installed but not started — the wizard brings it up after the admin picks a role)
- Runs database migrations and creates an admin account
After install, open https://<your-server-ip>:8443 and log in with the admin account created during installation.
The installer prompts for an admin account. If you pressed Enter to skip the password prompt, the default is:
| Field | Value |
|---|---|
| Username | admin (or whatever you entered) |
| Password | Password! |
You will be forced to change the password on first login and enroll TOTP MFA before you can access anything else. After MFA is set up, the install wizard launches — pick a role (Root / Intermediate / Issuing, any combination), bootstrap the CA, and you're running.
cd /path/to/forged-ca # wherever you cloned the repo
sudo ./update.shupdate.sh runs git pull, syncs files into /opt/forgedca/, updates dependencies, runs migrations, rebuilds Tailwind CSS, and restarts services. TLS certs, CA keys, .env, and the Postgres DB are preserved.
sudo ./uninstall.shRemoves all services, files, the system users, and both databases. /etc/step-ca/ first — the CA keys cannot be recovered.
Preserve data:
sudo ./uninstall.sh --keep-data- PKI engine: step-ca (we wrap and orchestrate — we do not reimplement)
- Web framework: Django 4.2 + HTMX
- UI framework: Tailwind CSS + DaisyUI
- Task queue: Celery + Redis
- Database: PostgreSQL (two logical DBs —
forgedcaandstep_ca) - Reverse proxy: nginx (TLS termination for the web UI)
- Federation: HTTPS + mTLS between nodes; dashboard aggregates peer status live on demand
See the full architecture plan in docs/roadmap.md and CLAUDE.md.
TBD. Will be one of MIT / Apache 2.0.
Issues, PRs, and feature requests welcome at https://github.com/ForgedIO/forged-ca.