Certificate Authority
A private certificate authority for internal TLS and mTLS. Issues Ed25519 certificates; each CA key is labelled with what seeded it (QuantumRand, or the OS CSPRNG if QuantumRand was unavailable). CSR submission, issuance, revocation, CRL and OCSP.
Ed25519 is classical cryptography — this is not post-quantum. Most web browsers do not accept Ed25519 certificates, so use it for internal services, not public websites. There is no ACME support (certbot will not work).
curl -X POST https://ca-api.qntyx.io/certificates/issue \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json"
https://ca-api.qntyx.io
| Method | Path | Description |
|---|---|---|
POST | /certificates/issue | Issue a certificate |
GET | /certificates/ | List certificates |
POST | /csr/submit | Submit a CSR |
POST | /revoke/{serial} | Revoke a certificate |
GET | /stats/ | Dashboard statistics |
All endpoints require a bearer token. See Authentication for details.
Manage this product visually at app-ca.qntyx.io
Learn more at ca.qntyx.io