Somewhat strangely, the description reminds me a lot of Active Directory Certificate Services.
AD setups are actually pretty complete if you ask me. Heck, OpenLDAP is a lot to setup vs AD. Same for cert management. User management. Machine management. Kerberos that works (since most don't even understand it: its a ticketing authentication system - the thing we keep recreating and calling it something else).
It goes a long way - and I'm glad more tools are coming to narrow these gaps!