Software Alternatives, Accelerators & Startups

BastionXP VS Dogtag PKI

Compare BastionXP VS Dogtag PKI and see what are their differences

BastionXP logo BastionXP

BastionXP Identity Based Infrastructure Access Platform is a Public Key Infrastructure (PKI) / Certificate Authority (CA) that creates, signs and distributes SSH, SSL X.509 certificates to servers and users upon successful SSO login via OAuth or SAML

Dogtag PKI logo Dogtag PKI

The Dogtag Certificate System is an enterprise-class open source Certificate Authority (CA).
  • BastionXP Landing page
    Landing page //
    2023-10-05

BastionXP is a Public Key Infrastructure (PKI) / Certificate Authority (CA) that creates, signs and distributes SSH, SSL/TLS X.509 certificates to servers and end users upon successful SSO login and 2FA authentication via OAuth providers such as GitHub, G-Suite, Microsoft Office 365, Okta and more.

BastionXP automates certificate management at scale, while simplifying your end-user workflow without compromising security.

BastionXP also has a built-in SSH proxy server that can be configured to function as an SSH bastion host. BastionXP works seamlessly with OpenSSH server and client software.

BastionXP offers Zero Trust Network Access(ZTNA) Security. All servers and end-users are required to authenticate with the BastionXP Authentication Server using an SSO and 2FA login, before access to the network can be granted.

BastionXP issues short-lived SSH, TLS/SSL X.509 certificates to end-users so that no user would have an indefinite access to any network resource. Moreover, these certificates, issued to a specific user based on Role Based Access Control(RBAC) can be used to access only a specific server(s) in the network. BastionXP provides you fine-grained control over who can access what resources in a network and for how long.

All network access events are logged and available for download, so that the logs can be analyzed using a log analyzer for anamoly detection.

BastionXP solution is available in three different formats:

Software Features Best Suited For
Free Software Version Limited features & best-effort support Hobbyists, educational purposes and non-commercial use cases.
Cloud-Hosted Version All enterprise features & priority customer support Small teams and Startups.
Self-Hosted Version All enterprise features & priority customer support Enterprises and Large Organizations.
  • Dogtag PKI Landing page
    Landing page //
    2022-03-17

BastionXP features and specs

  • SSH Certificate Manager: Yes
  • SSL Certificate Manager: Yes
  • Certificate Authority: Yes
  • Public Key Infrastructure: Yes
  • SSH Key Manager: Yes
  • Bastion Host or Jump Host: Yes
  • SSH Session Recording and Playback: Yes
  • Auditing and Logging: Yes

Dogtag PKI features and specs

No features have been listed yet.

BastionXP videos

BastionXP SSH Session Recording Demo

Dogtag PKI videos

No Dogtag PKI videos yet. You could help us improve this page by suggesting one.

+ Add video

Category Popularity

0-100% (relative to BastionXP and Dogtag PKI)
Identity And Access Management
Password Management
15 15%
85% 85
Network & Admin
0 0%
100% 100
SSL Certificates
100 100%
0% 0

User comments

Share your experience with using BastionXP and Dogtag PKI. For example, how are they different and which one is better?
Log in or Post with

What are some alternatives?

When comparing BastionXP and Dogtag PKI, you can also consider the following products

OpenXPKI - OpenXPKI is a software stack that provides all necessary components to manage keys and certificates...

OpenSSL - OpenSSL is a free and open source software cryptography library that implements both the Secure Sockets Layer (SSL) and the Transport Layer Security (TLS) protocols, which are primarily used to provide secure communications between web browsers and …

Teleport Database Access - Instant, secure, & privileged access to Postgres and MySQL

EJBCA - EJBCA® is a PKI Certificate Authority software, built using Java (JEE) technology.

Smallstep Certificates - A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.

AWS Certificate Manager - AWS Certificate Manager from Amazon Web Services (AWS)