Why ens0key
The market gives you three ways to solve certificate lifecycle — each with a catch. ens0key was built for the gap between them. Here is the comparison by category, honestly, including where we are not the right choice.
Why now: certificate lifetimes are collapsing
CA/Browser Forum ballot SC-081v3 (passed April 2025) caps the lifetime of publicly trusted TLS certificates on a fixed schedule. That is roughly 8× today's renewal volume by 2029 — annual renewals and spreadsheets are mathematically over. Every organization will need automation; the only question is how heavy it has to be.
Maximum validity of publicly trusted TLS certificates. OV/EV shorten on the same schedule.
Three ways the market solves this
Enterprise suites
Deep and proven at very large scale — but typically heavy: months-long rollouts, professional-services projects, six-figure licensing, and a substantial infrastructure stack underneath.
CA-bundled managers
Convenient if you buy that vendor's certificates — but lifecycle automation tends to stop at their own CA, the management plane is usually their cloud, and switching CAs often means switching platforms.
DIY & open source
Excellent renewal execution on the node where they run — but no inventory, no RBAC, no audit trail. The certificates nobody scripted still expire silently.
The gap: full lifecycle governance, CA-agnostic, on-prem and air-gap friendly — at a footprint and price a mid-size team can actually run. That is exactly where ens0key sits.
The market at a glance
A comparison of product categories, not specific vendors — individual products differ in detail.
| Criterion | ens0key | Enterprise suites | CA-bundled | DIY / OSS |
|---|---|---|---|---|
| Full lifecycle loop (discover → verify) | ✓ | ✓ | own CA only | — |
| CA-agnostic | ✓ | ✓ | — | ACME only |
| Own issuing CA (CRL/OCSP) | ✓ built in | typically fronts another CA | their CA | separate product |
| On-prem / air-gap | ✓ | varies | cloud | ✓ |
| Governance (RBAC, audit, approvals) | ✓ | ✓ | ✓ | — |
| Post-deploy verification + rollback | ✓ built in | typically scripted | — | you build it |
| Time to production | days–weeks | typically months | weeks | per node |
| Footprint | 1 binary + PostgreSQL | large stack | SaaS | engineer time |
Choosing by scenario — honestly
Everything between the extremes is exactly where ens0key fits best.
What we combine that others don't
Renewal with a safety net
Post-deploy TLS verification with automatic rollback, built into the product — the agent proves the new certificate is actually serving, or restores the previous one.
PKI in the box
A real issuing CA with CRL and OCSP responder — internal PKI without buying or running a second product.
Runs where suites can't
One Go binary + PostgreSQL, licensing verified fully offline (Ed25519), air-gap friendly, no phone-home.
A vendor you can reach
Store and CA integrations developed per customer and per use case — and maintained when third-party versions change. EN / HR / DE interface.
Compare us on your own infrastructure
- 0130-day trial — every feature, up to 10 managed certificates; register with us and you're off
- 02Guided POC: your network scanned and one service on verified auto-renewal
- 03An expired license never holds your data hostage — inventory, monitoring, discovery and reports keep working