Skip to content

Comment on OpenBAO: Manage, store, and distribute sensitive data

Comments

My dream configuration in the past was Vault, protected by step-ca's ACME implementation, with an IdP like KanIDM for SSO.

But it seems like there is so much feature creep: OpenBao now has its own ACME server. And KanIDM is considering it... Why is every app vying to be my root of trust?

Vault has had PKI since pre-v1; ACME was introduced in 2022 to modernize its APIs.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.