[THUGS(red)]

XXC Trust

A private certificate authority: root and intermediate CAs, CSR signing, ACME enrolment, a REST API, CRL/OCSP and expiry alerts, all in one workspace.

Infrastructure live
ca.xxc.dk open ↗

The whole certificate lifecycle for a private PKI, from the first signature to the final revocation. Build root and intermediate authorities, issue certificates from template policies that cap validity, key generation, usage and allowed domains, or sign your own CSR, and download PEM, DER, full chains or a protected PKCS#12. Automate it through a REST API with scoped bearer tokens or an ACME directory — DNS-01 and HTTP-01, external account binding, so certbot works against it unchanged. Revocation is published over CRL and OCSP, expiry alerts go to Discord, Slack, Teams or an HMAC-signed webhook, and role-based access, multi-factor authentication and an audit trail cover the people side, and stored data is encrypted at rest. It is a private CA, so its root has to be installed in the clients that should trust it.

pki x509 acme certificates ocsp self-hosted

go to ca.xxc.dk