SecCert — internal ACME certificate authority¶
SecCert is a self-hosted ACME (RFC 8555)
certificate authority for closed and air-gapped networks. Point any standard ACME client
(certbot, acme.sh, Caddy, Traefik, lego, step) at it and your internal services get
short-lived, auto-renewing certs from a CA you run and trust — a tiny Let’s Encrypt for your
.mil/.internal network, with no path to the public internet required.
It’s deployed first on every suite target, as the internal CA every other component trusts.
What it does¶
Standards-based — real RFC 8555. Existing ACME clients work unmodified.
Two-tier PKI — a self-signed Root signs an Intermediate; only the Intermediate signs leaves. Publish the Root once as your enclave’s trust anchor.
Fully offline — key generation, issuance, and validation all happen in-network. No telemetry, no external calls.
Small and auditable — Python + FastAPI +
cryptography, one container, SQLite state, and a hash-chained, tamper-evident issuance ledger.Admin console at
/admin— list and inspect issued certificates, revoke, download the Root, and see CA info. Gated by a bearer token, or optionally SecSSO login.
Quickstart¶
docker run -d --name seccert \
-p 14000:14000 \
-v seccert-data:/var/lib/seccert \
-e SECCERT_EXTERNAL_URL=http://ca.internal.example:14000 \
ghcr.io/secrouter/seccert:latest
On first boot SecCert generates the Root + Intermediate and prints the admin token — grab the
trust anchor at /ca.crt and point an ACME client’s directory at /acme/directory.
Learn more¶
SecCert on GitHub — source, issues, releases.
SecCert docs — deployment, ACME client integration, trust-anchor distribution, security posture, and the full environment variable / endpoint reference.