Your PKI,
one install away.
The self-hosted certificate authority with a modern webย UI. Create, manage, discover and automate your certificates. Noย YAML, noย CLI expertise needed.
docker run -d -p 8443:8443 neyslim/ultimate-ca-manager Latest release v2.235 , 26 September 2026
Up and running in 60 seconds
Choose your platform. One command, full PKI.
docker run -d --restart=unless-stopped \
--name ucm \
-p 8443:8443 \
-p 8080:8080 \
-v ucm-data:/opt/ucm/data \
neyslim/ultimate-ca-manager:latest
Then open
https://localhost:8443
and log in with
admin /
changeme123
A complete PKI platform,
not just a CLI tool.
Everything from your root CA down to network discovery, in one self-hosted app.
CA Hierarchy
Build complete trust chains from the web UI, without openssl gymnastics.
- Root & intermediate CAs
- Offline, HSM-backed or externally signed
- RFC 5280 name constraints
- Revoke an intermediate from its parent
Certificate Lifecycle
Issue, sign, renew, revoke and export, in bulk when you need it.
- In-place renewal keeps the same ID
- PKCS#12, PEM, DER and JKS export
- Approval workflows on every path
- RFC 5280 / CA-B Forum linting
ACME Server
RFC 8555 with ARI, EAB and named profiles. certbot, acme.sh, Caddy, cert-manager.
Windows Enrollment
Autoenrollment over XCEP/WSTEP, or sign through an existing AD CS.
SCEP & EST
RFC 8894 and RFC 7030, several endpoints, each with its own CA and rules.
Discovery
Scan the network, find every certificate, tell the managed from the rest.
Deploy Hooks
Push a renewed certificate to the host that serves it, over SSH, and reload it.
HSM & Key Recovery
PKCS#11, Azure Key Vault, Cloud KMS. Archived keys come back under four eyes.
SSH CA
Sign user and host keys, ship the trust config as a one-line setup script.
CRL, OCSP & TSA
Delta CRL, delegated OCSP responder, RFC 3161 timestamping.
A UI you'll actually want to use
Not just a CLI with a web wrapper. A real, modern interface, on desktop and mobile.
Fully responsive
Manage your PKI from any device.