pyCA (see http://www.pyca.de) is a collection of Python wrapper scripts and CGI-BINs for setting up a X.509 CA based on OpenSSL. Issued client certificates can be replicated to existing LDAP entries.
