PKI/CA Management with SCEP, OCSP, ACME, CRL. WebAuthn, mTLS, multi-arch Docker.
50K+
Web-based Certificate Authority management with PKI protocol support.
UCM manages the whole certificate lifecycle from a web UI: CA hierarchy, issuance and renewal, the protocols your clients already speak (ACME, SCEP, EST, OCSP, CRL, TSA), Windows autoenrollment, SSH certificates, and discovery of what is already deployed on your network.
Multi-arch: linux/amd64, linux/arm64

docker volume create ucm-data
docker volume create ucm-config
docker run -d \
--name ucm \
-p 8443:8443 \
-p 8080:8080 \
-v ucm-data:/opt/ucm/data \
-v ucm-config:/etc/ucm \
--restart unless-stopped \
neyslim/ultimate-ca-manager:latest
Access: https://localhost:8443 Credentials: admin / changeme123, changed on first login.
Mount
/etc/ucm. It holdsmaster.key, which decrypts every private key in the database. The image declares it as a volume, so leaving it unmounted creates an anonymous one: recreate the container and the key is gone, along with any chance of reading the keys it protected.
services:
ucm:
image: neyslim/ultimate-ca-manager:latest
container_name: ucm
ports:
- "8443:8443"
- "8080:8080" # HTTP, for the public CRL/CDP and OCSP endpoints
volumes:
- ucm-data:/opt/ucm/data
- ucm-config:/etc/ucm
environment:
- UCM_FQDN=ucm.example.com
restart: unless-stopped
volumes:
ucm-data:
ucm-config:
| Component | Technology |
|---|---|
| Frontend | React 18, Vite, Radix UI |
| Backend | Python 3.13, Flask, SQLAlchemy |
| Database | SQLite by default, or native PostgreSQL |
| Server | Gunicorn + gevent WebSocket |
| Auth | Session cookies, WebAuthn/FIDO2, TOTP, mTLS |
| Variable | Default | Description |
|---|---|---|
UCM_FQDN | ucm.local | Server FQDN, used in the URLs UCM advertises |
UCM_HTTPS_PORT | 8443 | HTTPS port |
UCM_HTTP_PORT | 8080 | Plain HTTP port for CRL/CDP and OCSP |
UCM_SECRET_KEY | generated | Session secret |
DATABASE_URL | unset | PostgreSQL DSN; SQLite is used when unset |
KEY_ENCRYPTION_KEY | unset | Encrypts private keys at rest, in place of the master.key file |
UCM_ACME_ENABLED | true | Enable the ACME server |
UCM_SMTP_ENABLED | false | Enable email notifications |
latest -- Latest stable release2.230, 2.231)Release candidates are published under their own X.Y-rcN tag and never move latest.
python:3.13-slim-bookwormucm)ghcr.io/neyslim/ultimate-ca-managerTwo volumes, both needed:
| Path | Holds |
|---|---|
/opt/ucm/data | Database, CA files, issued certificates, backups, HTTPS certificate |
/etc/ucm | master.key, which decrypts the private keys in the database |
A backup of one without the other restores to an instance that cannot read its own keys.
# Backup, both volumes
docker run --rm -v ucm-data:/data -v ucm-config:/config -v $(pwd):/backup \
alpine tar czf /backup/ucm-backup.tar.gz -C / data config
# Restore
docker run --rm -v ucm-data:/data -v ucm-config:/config -v $(pwd):/backup \
alpine tar xzf /backup/ucm-backup.tar.gz -C /
UCM also takes its own encrypted backups, on a schedule, from Settings > Backup. Those carry the key material they need and are restored from the interface.
# Source
docker stop ucm
docker run --rm -v ucm-data:/data -v ucm-config:/config -v $(pwd):/backup \
alpine tar czf /backup/ucm-move.tar.gz -C / data config
scp ucm-move.tar.gz user@new-host:~/
# Destination
docker volume create ucm-data && docker volume create ucm-config
docker run --rm -v ucm-data:/data -v ucm-config:/config -v $(pwd):/backup \
alpine tar xzf /backup/ucm-move.tar.gz -C /
# then start the container as usual
BSD 3-Clause License with Commons Clause.
Content type
Image
Digest
sha256:db77305f6…
Size
330.2 MB
Last updated
7 days ago
docker pull neyslim/ultimate-ca-manager