Operator · What You're Running

Engine, Not Portal

Frame 22 of 107

You have stood up a CA, issued from it, and put your own hierarchy behind the console. This section names the concepts behind what you just did — starting with what goca deliberately is not. Where is the portal? The self-service page, the discovery scanner, the expiry emails to certificate owners? Not here — on purpose. goca (the goca engine) is a certificate authority engine: the hardened core that generates and custodies CA keys, evaluates issuance policy, signs certificates and revocation data, and keeps a cryptographically verifiable record of everything it did.

It is deliberately headless. No end-user portal, no discovery scanner, no owner notifications — those belong to the RA/CLM layer you put in front of it: Keyfactor Command, Venafi, an in-house RA, or, for machine enrollment, the bundled protocol heads. The admin console that ships with goca is an operator console for the people who run the CA, not a portal for the people who consume certificates.

Metaphor: goca is the engine block, not the dashboard. You judge it by compression and custody, not by cupholders.
Where it breaks: an engine block does nothing alone; goca does — console, REST API and ACME make it drivable by itself for machine enrollment. What it refuses to be is the showroom.

Now I can say what goca is — and what layer I still need in front of it.