updated README.md, added LICENSE and changed TolaMironcenkoCA to root
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2024 Tola Mironcenko
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
@@ -1,28 +1,280 @@
|
||||
# scm - SSL Certificate Manager
|
||||
# SCM - SSL Certificate Manager
|
||||
|
||||
## endpoints
|
||||
A Go-based SSL Certificate Manager that provides a REST API for managing SSL certificates. The system allows you to create, view, and delete SSL certificates signed by a Certificate Authority (CA).
|
||||
|
||||
- `/api/certs` - get all certificates and details
|
||||
- `/api/certs/create` - create a new certificate
|
||||
- `/api/certs/delete` - delete a certificate
|
||||
## Features
|
||||
|
||||
## build
|
||||
- **Certificate Management**: Create, list, and delete SSL certificates
|
||||
- **CA Integration**: Uses a root Certificate Authority to sign certificates
|
||||
- **REST API**: Simple HTTP endpoints for certificate operations
|
||||
- **TLS Support**: Configurable HTTPS server with certificate validation
|
||||
- **Certificate Parsing**: Detailed certificate information extraction
|
||||
- **File System Storage**: Organized certificate storage in directories
|
||||
|
||||
```shell
|
||||
## Project Structure
|
||||
|
||||
```
|
||||
backend/
|
||||
├── api/ # HTTP handlers and API endpoints
|
||||
│ ├── Certs.go # List certificates endpoint
|
||||
│ ├── CreateCert.go # Create certificate endpoint
|
||||
│ ├── DeleteCert.go # Delete certificate endpoint
|
||||
│ ├── Spa.go # Single-page application handler
|
||||
│ └── frontend/ # Frontend assets
|
||||
├── model/ # Data structures and models
|
||||
│ ├── CreateCertRequest.go
|
||||
│ └── DeleteCertRequest.go
|
||||
├── server/ # Server configuration and setup
|
||||
├── utils/ # Utility functions
|
||||
│ ├── CheckExistsOrCreateDir.go
|
||||
│ ├── CreateServerCert.go
|
||||
│ ├── LoadEnv.go
|
||||
│ ├── LoadRootCertAndKey.go
|
||||
│ ├── ParseCert.go
|
||||
│ └── SavePEMFile.go
|
||||
├── main.go # Application entry point
|
||||
├── go.mod # Go module definition
|
||||
└── scm.conf # Configuration file
|
||||
```
|
||||
|
||||
## Requirements
|
||||
|
||||
- Go 1.24.5 or higher
|
||||
- Root Certificate Authority (CA) certificate and private key
|
||||
- Linux/Unix environment (recommended)
|
||||
|
||||
## Installation
|
||||
|
||||
1. Clone the repository:
|
||||
```bash
|
||||
git clone <repository-url>
|
||||
cd backend
|
||||
```
|
||||
|
||||
2. Install dependencies:
|
||||
```bash
|
||||
go mod tidy
|
||||
```
|
||||
|
||||
3. Build the application:
|
||||
```bash
|
||||
go build -o scm
|
||||
```
|
||||
|
||||
## configuration
|
||||
## Configuration
|
||||
|
||||
### example config file - scm.conf
|
||||
Create a configuration file `scm.conf` in the project root:
|
||||
|
||||
```
|
||||
```bash
|
||||
# TLS Configuration
|
||||
ENABLE_TLS=true
|
||||
CERT_FILE=/home/tola/certs/localhost/localhost.crt
|
||||
KEY_FILE=/home/tola/certs/localhost/localhost.key
|
||||
CERT_FILE=/path/to/server/certificate.crt
|
||||
KEY_FILE=/path/to/server/private.key
|
||||
|
||||
CERTS_PATH=/home/tola/certs
|
||||
# Certificate Storage
|
||||
CERTS_PATH=/path/to/certificates/directory
|
||||
|
||||
# Server Configuration
|
||||
SERVER_ADDRESS=0.0.0.0
|
||||
SERVER_PORT=8777
|
||||
```
|
||||
|
||||
### Configuration Parameters
|
||||
|
||||
| Parameter | Description | Default | Required |
|
||||
|-----------|-------------|---------|----------|
|
||||
| `ENABLE_TLS` | Enable HTTPS server | `false` | No |
|
||||
| `CERT_FILE` | Path to server certificate | - | If TLS enabled |
|
||||
| `KEY_FILE` | Path to server private key | - | If TLS enabled |
|
||||
| `CERTS_PATH` | Directory for certificate storage | - | Yes |
|
||||
| `SERVER_ADDRESS` | Server bind address | `0.0.0.0` | No |
|
||||
| `SERVER_PORT` | Server port | `8080` | No |
|
||||
|
||||
## Certificate Authority Setup
|
||||
|
||||
Before using the certificate manager, you need to set up a root CA:
|
||||
|
||||
1. Create a root CA directory:
|
||||
```bash
|
||||
mkdir -p /path/to/certificates/root
|
||||
```
|
||||
|
||||
2. Place your root CA certificate and private key:
|
||||
```bash
|
||||
# Certificate: /path/to/certificates/root/root.crt
|
||||
# Private Key: /path/to/certificates/root/root.key
|
||||
```
|
||||
|
||||
## API Endpoints
|
||||
|
||||
### GET /api/certs
|
||||
List all managed certificates with details.
|
||||
|
||||
**Response:**
|
||||
```json
|
||||
[
|
||||
{
|
||||
"id": "uuid-string",
|
||||
"domain": "example.com",
|
||||
"href": "https://example.com",
|
||||
"cert": "-----BEGIN CERTIFICATE-----...",
|
||||
"key": "-----BEGIN PRIVATE KEY-----...",
|
||||
"certinfo": {
|
||||
"issuer": "CA Name",
|
||||
"subject": "CN=example.com",
|
||||
"notBefore": "2024-01-01T00:00:00Z",
|
||||
"notAfter": "2025-01-01T00:00:00Z",
|
||||
"serialNumber": "123456"
|
||||
}
|
||||
}
|
||||
]
|
||||
```
|
||||
|
||||
### POST /api/certs/create
|
||||
Create a new SSL certificate.
|
||||
|
||||
**Request Body:**
|
||||
```json
|
||||
{
|
||||
"commonname": "example.com",
|
||||
"organizationname": ["Your Organization"],
|
||||
"organizationunit": ["IT Department"],
|
||||
"dns": ["example.com", "www.example.com"],
|
||||
"password": "ca-private-key-password"
|
||||
}
|
||||
```
|
||||
|
||||
**Response:**
|
||||
```json
|
||||
{
|
||||
"status": "success",
|
||||
"message": "Certificate created successfully"
|
||||
}
|
||||
```
|
||||
|
||||
### POST /api/certs/delete
|
||||
Delete an existing certificate.
|
||||
|
||||
**Request Body:**
|
||||
```json
|
||||
{
|
||||
"domain": "example.com"
|
||||
}
|
||||
```
|
||||
|
||||
## Usage
|
||||
|
||||
1. Start the server:
|
||||
```bash
|
||||
./scm
|
||||
```
|
||||
|
||||
2. Create a certificate:
|
||||
```bash
|
||||
curl -X POST http://localhost:8777/api/certs/create \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{
|
||||
"commonname": "example.com",
|
||||
"organizationname": ["My Company"],
|
||||
"organizationunit": ["IT"],
|
||||
"dns": ["example.com", "www.example.com"],
|
||||
"password": "your-ca-key-password"
|
||||
}'
|
||||
```
|
||||
|
||||
3. List certificates:
|
||||
```bash
|
||||
curl http://localhost:8777/api/certs
|
||||
```
|
||||
|
||||
4. Delete a certificate:
|
||||
```bash
|
||||
curl -X POST http://localhost:8777/api/certs/delete \
|
||||
-H "Content-Type: application/json" \
|
||||
-d '{"domain": "example.com"}'
|
||||
```
|
||||
|
||||
## Development
|
||||
|
||||
### Dependencies
|
||||
|
||||
- `github.com/google/uuid` - UUID generation
|
||||
- `github.com/joho/godotenv` - Environment variable loading
|
||||
- `github.com/youmark/pkcs8` - PKCS#8 key handling
|
||||
- `golang.org/x/crypto` - Cryptographic operations
|
||||
|
||||
### Running in Development
|
||||
|
||||
```bash
|
||||
# Install dependencies
|
||||
go mod tidy
|
||||
|
||||
# Run the application
|
||||
go run main.go
|
||||
|
||||
# Or build and run
|
||||
go build -o scm && ./scm
|
||||
```
|
||||
|
||||
### Testing
|
||||
|
||||
```bash
|
||||
# Run tests
|
||||
go test ./...
|
||||
|
||||
# Run tests with verbose output
|
||||
go test -v ./...
|
||||
```
|
||||
|
||||
## Security Considerations
|
||||
|
||||
- Store CA private keys securely and use strong passwords
|
||||
- Implement proper access controls for the API endpoints
|
||||
- Use HTTPS in production environments
|
||||
- Regularly rotate certificates and CA keys
|
||||
- Validate input data to prevent injection attacks
|
||||
- Monitor certificate expiration dates
|
||||
|
||||
## File Organization
|
||||
|
||||
Certificates are stored in the following structure:
|
||||
```
|
||||
CERTS_PATH/
|
||||
├── root/
|
||||
│ ├── root.crt # Root CA certificate
|
||||
│ └── root.key # Root CA private key
|
||||
├── example.com/
|
||||
│ ├── example.com.crt # Domain certificate
|
||||
│ └── example.com.key # Domain private key
|
||||
└── another-domain.com/
|
||||
├── another-domain.com.crt
|
||||
└── another-domain.com.key
|
||||
```
|
||||
|
||||
## Troubleshooting
|
||||
|
||||
### Common Issues
|
||||
|
||||
1. **"Certificate not found"** - Ensure the CERTS_PATH is correctly configured
|
||||
2. **"Invalid CA password"** - Verify the CA private key password
|
||||
3. **"Permission denied"** - Check file system permissions for certificate directories
|
||||
4. **"Port already in use"** - Change the SERVER_PORT in configuration
|
||||
|
||||
### Logs
|
||||
|
||||
The application logs to stdout. For production, consider redirecting logs to a file:
|
||||
```bash
|
||||
./scm >> /var/log/scm.log 2>&1
|
||||
```
|
||||
|
||||
## Contributing
|
||||
|
||||
1. Fork the repository
|
||||
2. Create a feature branch
|
||||
3. Make your changes
|
||||
4. Add tests for new functionality
|
||||
5. Submit a pull request
|
||||
|
||||
## License
|
||||
|
||||
This project is licensed under the MIT License. See LICENSE file for details.
|
||||
|
||||
+2
-2
@@ -27,13 +27,13 @@ func CreateCert(w http.ResponseWriter, r *http.Request) {
|
||||
"%s/%s/%s.crt",
|
||||
os.Getenv("CERTS_PATH"),
|
||||
"root",
|
||||
"TolaMironcenkoCA",
|
||||
"root",
|
||||
),
|
||||
fmt.Sprintf(
|
||||
"%s/%s/%s.key",
|
||||
os.Getenv("CERTS_PATH"),
|
||||
"root",
|
||||
"TolaMironcenkoCA",
|
||||
"root",
|
||||
),
|
||||
requestData.CAKeyPassword,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user