The problem
Shorter lifetimes. Stricter auditors. Same team.
cert-manager solved issuing certificates. It never answered who was allowed to ask, who signed off, or how you prove it a year later. As lifetimes shrink and supervisors tighten, that gap stops being a nuisance and turns into an audit finding.
Outages still happen
of organisations had a certificate-related outage in the past year.
CyberArk, State of Machine Identity Security 2025Renewals multiply
more renewals per certificate as public TLS lifetimes fall from 398 to 47 days by 2029.
Derived from CA/Browser Forum ballot SC-081v3 (398 ÷ 47 days)PQC roadmaps are rare
of Swiss financial institutions surveyed by FINMA have a specific roadmap to quantum-safe cryptography.
FINMA Guidance 05/2026FINMA recommends a post-quantum strategy and migration roadmap by mid-2027 — and that starts with knowing which cryptography you use where. 76% of the institutions FINMA surveyed see significant value in exactly that inventory. OpenPKI keeps it as a side effect of issuing, not as a separate project.