updated README.md, added LICENSE and changed TolaMironcenkoCA to root

This commit is contained in:
wt
2025-07-16 14:28:18 +07:00
parent 3b78352109
commit 4ad498ebb3
3 changed files with 288 additions and 15 deletions
+21
View File
@@ -0,0 +1,21 @@
MIT License
Copyright (c) 2024 Tola Mironcenko
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
+265 -13
View File
@@ -1,28 +1,280 @@
# scm - SSL Certificate Manager
# SCM - SSL Certificate Manager
## endpoints
A Go-based SSL Certificate Manager that provides a REST API for managing SSL certificates. The system allows you to create, view, and delete SSL certificates signed by a Certificate Authority (CA).
- `/api/certs` - get all certificates and details
- `/api/certs/create` - create a new certificate
- `/api/certs/delete` - delete a certificate
## Features
## build
- **Certificate Management**: Create, list, and delete SSL certificates
- **CA Integration**: Uses a root Certificate Authority to sign certificates
- **REST API**: Simple HTTP endpoints for certificate operations
- **TLS Support**: Configurable HTTPS server with certificate validation
- **Certificate Parsing**: Detailed certificate information extraction
- **File System Storage**: Organized certificate storage in directories
```shell
## Project Structure
```
backend/
├── api/ # HTTP handlers and API endpoints
│ ├── Certs.go # List certificates endpoint
│ ├── CreateCert.go # Create certificate endpoint
│ ├── DeleteCert.go # Delete certificate endpoint
│ ├── Spa.go # Single-page application handler
│ └── frontend/ # Frontend assets
├── model/ # Data structures and models
│ ├── CreateCertRequest.go
│ └── DeleteCertRequest.go
├── server/ # Server configuration and setup
├── utils/ # Utility functions
│ ├── CheckExistsOrCreateDir.go
│ ├── CreateServerCert.go
│ ├── LoadEnv.go
│ ├── LoadRootCertAndKey.go
│ ├── ParseCert.go
│ └── SavePEMFile.go
├── main.go # Application entry point
├── go.mod # Go module definition
└── scm.conf # Configuration file
```
## Requirements
- Go 1.24.5 or higher
- Root Certificate Authority (CA) certificate and private key
- Linux/Unix environment (recommended)
## Installation
1. Clone the repository:
```bash
git clone <repository-url>
cd backend
```
2. Install dependencies:
```bash
go mod tidy
```
3. Build the application:
```bash
go build -o scm
```
## configuration
## Configuration
### example config file - scm.conf
Create a configuration file `scm.conf` in the project root:
```
```bash
# TLS Configuration
ENABLE_TLS=true
CERT_FILE=/home/tola/certs/localhost/localhost.crt
KEY_FILE=/home/tola/certs/localhost/localhost.key
CERT_FILE=/path/to/server/certificate.crt
KEY_FILE=/path/to/server/private.key
CERTS_PATH=/home/tola/certs
# Certificate Storage
CERTS_PATH=/path/to/certificates/directory
# Server Configuration
SERVER_ADDRESS=0.0.0.0
SERVER_PORT=8777
```
### Configuration Parameters
| Parameter | Description | Default | Required |
|-----------|-------------|---------|----------|
| `ENABLE_TLS` | Enable HTTPS server | `false` | No |
| `CERT_FILE` | Path to server certificate | - | If TLS enabled |
| `KEY_FILE` | Path to server private key | - | If TLS enabled |
| `CERTS_PATH` | Directory for certificate storage | - | Yes |
| `SERVER_ADDRESS` | Server bind address | `0.0.0.0` | No |
| `SERVER_PORT` | Server port | `8080` | No |
## Certificate Authority Setup
Before using the certificate manager, you need to set up a root CA:
1. Create a root CA directory:
```bash
mkdir -p /path/to/certificates/root
```
2. Place your root CA certificate and private key:
```bash
# Certificate: /path/to/certificates/root/root.crt
# Private Key: /path/to/certificates/root/root.key
```
## API Endpoints
### GET /api/certs
List all managed certificates with details.
**Response:**
```json
[
{
"id": "uuid-string",
"domain": "example.com",
"href": "https://example.com",
"cert": "-----BEGIN CERTIFICATE-----...",
"key": "-----BEGIN PRIVATE KEY-----...",
"certinfo": {
"issuer": "CA Name",
"subject": "CN=example.com",
"notBefore": "2024-01-01T00:00:00Z",
"notAfter": "2025-01-01T00:00:00Z",
"serialNumber": "123456"
}
}
]
```
### POST /api/certs/create
Create a new SSL certificate.
**Request Body:**
```json
{
"commonname": "example.com",
"organizationname": ["Your Organization"],
"organizationunit": ["IT Department"],
"dns": ["example.com", "www.example.com"],
"password": "ca-private-key-password"
}
```
**Response:**
```json
{
"status": "success",
"message": "Certificate created successfully"
}
```
### POST /api/certs/delete
Delete an existing certificate.
**Request Body:**
```json
{
"domain": "example.com"
}
```
## Usage
1. Start the server:
```bash
./scm
```
2. Create a certificate:
```bash
curl -X POST http://localhost:8777/api/certs/create \
-H "Content-Type: application/json" \
-d '{
"commonname": "example.com",
"organizationname": ["My Company"],
"organizationunit": ["IT"],
"dns": ["example.com", "www.example.com"],
"password": "your-ca-key-password"
}'
```
3. List certificates:
```bash
curl http://localhost:8777/api/certs
```
4. Delete a certificate:
```bash
curl -X POST http://localhost:8777/api/certs/delete \
-H "Content-Type: application/json" \
-d '{"domain": "example.com"}'
```
## Development
### Dependencies
- `github.com/google/uuid` - UUID generation
- `github.com/joho/godotenv` - Environment variable loading
- `github.com/youmark/pkcs8` - PKCS#8 key handling
- `golang.org/x/crypto` - Cryptographic operations
### Running in Development
```bash
# Install dependencies
go mod tidy
# Run the application
go run main.go
# Or build and run
go build -o scm && ./scm
```
### Testing
```bash
# Run tests
go test ./...
# Run tests with verbose output
go test -v ./...
```
## Security Considerations
- Store CA private keys securely and use strong passwords
- Implement proper access controls for the API endpoints
- Use HTTPS in production environments
- Regularly rotate certificates and CA keys
- Validate input data to prevent injection attacks
- Monitor certificate expiration dates
## File Organization
Certificates are stored in the following structure:
```
CERTS_PATH/
├── root/
│ ├── root.crt # Root CA certificate
│ └── root.key # Root CA private key
├── example.com/
│ ├── example.com.crt # Domain certificate
│ └── example.com.key # Domain private key
└── another-domain.com/
├── another-domain.com.crt
└── another-domain.com.key
```
## Troubleshooting
### Common Issues
1. **"Certificate not found"** - Ensure the CERTS_PATH is correctly configured
2. **"Invalid CA password"** - Verify the CA private key password
3. **"Permission denied"** - Check file system permissions for certificate directories
4. **"Port already in use"** - Change the SERVER_PORT in configuration
### Logs
The application logs to stdout. For production, consider redirecting logs to a file:
```bash
./scm >> /var/log/scm.log 2>&1
```
## Contributing
1. Fork the repository
2. Create a feature branch
3. Make your changes
4. Add tests for new functionality
5. Submit a pull request
## License
This project is licensed under the MIT License. See LICENSE file for details.
+2 -2
View File
@@ -27,13 +27,13 @@ func CreateCert(w http.ResponseWriter, r *http.Request) {
"%s/%s/%s.crt",
os.Getenv("CERTS_PATH"),
"root",
"TolaMironcenkoCA",
"root",
),
fmt.Sprintf(
"%s/%s/%s.key",
os.Getenv("CERTS_PATH"),
"root",
"TolaMironcenkoCA",
"root",
),
requestData.CAKeyPassword,
)