we just released an open source PKI engine [0] as part of the wider Infisical secret management toolset. With Infisical PKI, you can:
- create root and intermediary CAs;
- issue and revoke x.509 certificates (with support for CRL);
- encrypt TLS communication channels and authenticate users, computers, IoT devices, etc.
It is available under the MIT license as part of the main Infisical repository [1]
[0] https://infisical.com/docs/documentation/platform/pki/overvi...
[1] https://github.com/Infisical/infisical