Like all good product ideas, it started with a frustrating problem that seemed to lack a simple solution. Not that there weren’t many solutions out there that could solve one part of the problem, but I couldn’t find a simple, cost-effective, all-encompassing option.
The problem
I needed to manage an increasing number of encryption keys and SSL certificates. Why? Well, we were providing integration services for our clients in a space where security and data encryption were essential.
We were managing the technical implementation on behalf of our clients and therefore had the responsibility of generating, renewing, and managing the keys and certificates required by each integration platform. These then needed to be applied to the integration, with public keys sent to the third party.
Keys and certs were generating for test, pre-production, and production environments, requirements differed for each project, and the complexity gradually increased with these factors.
There are many more details to these projects that I won’t specify, but all-in-all it was become an annoying and unsustainable manual burden on (mostly) my shoulders.
So I went searching for the solution and surprisingly couldn’t really find what I was after (perhaps I didn’t look hard enough, but here we are…).
Cloud key management services (KMS)
An obvious thought was to use the key management services provided by AWS, Azure, or another cloud provider, which would integrate very nicely with our cloud-deployed services. But this seemed unexpectedly limited.
- You can’t generate PGP keys or CSRs within the platform.
- Certificates must be imported in specific formats (usually not what I had at hand).
- It just seemed rather clunky and cumbersome.
Password managers
We could use our existing password manager as a “secrets manager” but this would be limited in similar ways. The only advantage would have been the centralized management.
After all, password managers are designed for… passwords! And yes, of course, they are much more powerful than just autofilling my login credentials, but still not what I was after.
Enterprise vaults
Then we come to the big guys. Enterprise PKI solutions, like Hashicorp Vault. Amazing products, cutting-edge security features, a lot to like.
But at the end of the day - complicated and expensive.
I just wanted something simple to use and reasonable on the budget.
The simple solution
So after much frustration, I decided to just built it myself. And thus was born SimpleKrypt. It’s what I need.
- Generate PGP or SSH key pairs and Certificate Signing Requests (CSRs).
- Store secrets and secure notes.
- Securely send messages with expiring links.
- Manage it all in a simple web application.
- Uncompromising on security.
Given it solved my problems, I figured there was a chance it might be useful to others as well.
What’s next
API access and cloud KMS sync are on the roadmap, along with a number of enhancements to integrate SimpleKrypt into more workflows.
But for now, I’d love for you to try it. Create a free account, import a few keys and certificates, and see if it meets your needs.
If you have any frustrations with the existing functionality, any requests for new features, or really anything at all, drop me a line — I’d rather hear what’s missing quickly so I can improve the product and make life simpler for many more of you.
– Jonathan