From 4ad498ebb302769f9dc1acd0be017f681b6ff81c Mon Sep 17 00:00:00 2001 From: TolaMironcenko Date: Wed, 16 Jul 2025 14:28:18 +0700 Subject: [PATCH] updated README.md, added LICENSE and changed TolaMironcenkoCA to root --- LICENSE | 21 ++++ README.md | 278 +++++++++++++++++++++++++++++++++++++++++++--- api/CreateCert.go | 4 +- 3 files changed, 288 insertions(+), 15 deletions(-) create mode 100644 LICENSE diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..6f1d252 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2024 Tola Mironcenko + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md index 0370b0b..1475525 100644 --- a/README.md +++ b/README.md @@ -1,28 +1,280 @@ -# scm - SSL Certificate Manager +# SCM - SSL Certificate Manager -## endpoints +A Go-based SSL Certificate Manager that provides a REST API for managing SSL certificates. The system allows you to create, view, and delete SSL certificates signed by a Certificate Authority (CA). -- `/api/certs` - get all certificates and details -- `/api/certs/create` - create a new certificate -- `/api/certs/delete` - delete a certificate +## Features -## build +- **Certificate Management**: Create, list, and delete SSL certificates +- **CA Integration**: Uses a root Certificate Authority to sign certificates +- **REST API**: Simple HTTP endpoints for certificate operations +- **TLS Support**: Configurable HTTPS server with certificate validation +- **Certificate Parsing**: Detailed certificate information extraction +- **File System Storage**: Organized certificate storage in directories -```shell +## Project Structure + +``` +backend/ +├── api/ # HTTP handlers and API endpoints +│ ├── Certs.go # List certificates endpoint +│ ├── CreateCert.go # Create certificate endpoint +│ ├── DeleteCert.go # Delete certificate endpoint +│ ├── Spa.go # Single-page application handler +│ └── frontend/ # Frontend assets +├── model/ # Data structures and models +│ ├── CreateCertRequest.go +│ └── DeleteCertRequest.go +├── server/ # Server configuration and setup +├── utils/ # Utility functions +│ ├── CheckExistsOrCreateDir.go +│ ├── CreateServerCert.go +│ ├── LoadEnv.go +│ ├── LoadRootCertAndKey.go +│ ├── ParseCert.go +│ └── SavePEMFile.go +├── main.go # Application entry point +├── go.mod # Go module definition +└── scm.conf # Configuration file +``` + +## Requirements + +- Go 1.24.5 or higher +- Root Certificate Authority (CA) certificate and private key +- Linux/Unix environment (recommended) + +## Installation + +1. Clone the repository: +```bash +git clone +cd backend +``` + +2. Install dependencies: +```bash +go mod tidy +``` + +3. Build the application: +```bash go build -o scm ``` -## configuration +## Configuration -### example config file - scm.conf +Create a configuration file `scm.conf` in the project root: -``` +```bash +# TLS Configuration ENABLE_TLS=true -CERT_FILE=/home/tola/certs/localhost/localhost.crt -KEY_FILE=/home/tola/certs/localhost/localhost.key +CERT_FILE=/path/to/server/certificate.crt +KEY_FILE=/path/to/server/private.key -CERTS_PATH=/home/tola/certs +# Certificate Storage +CERTS_PATH=/path/to/certificates/directory +# Server Configuration SERVER_ADDRESS=0.0.0.0 SERVER_PORT=8777 ``` + +### Configuration Parameters + +| Parameter | Description | Default | Required | +|-----------|-------------|---------|----------| +| `ENABLE_TLS` | Enable HTTPS server | `false` | No | +| `CERT_FILE` | Path to server certificate | - | If TLS enabled | +| `KEY_FILE` | Path to server private key | - | If TLS enabled | +| `CERTS_PATH` | Directory for certificate storage | - | Yes | +| `SERVER_ADDRESS` | Server bind address | `0.0.0.0` | No | +| `SERVER_PORT` | Server port | `8080` | No | + +## Certificate Authority Setup + +Before using the certificate manager, you need to set up a root CA: + +1. Create a root CA directory: +```bash +mkdir -p /path/to/certificates/root +``` + +2. Place your root CA certificate and private key: +```bash +# Certificate: /path/to/certificates/root/root.crt +# Private Key: /path/to/certificates/root/root.key +``` + +## API Endpoints + +### GET /api/certs +List all managed certificates with details. + +**Response:** +```json +[ + { + "id": "uuid-string", + "domain": "example.com", + "href": "https://example.com", + "cert": "-----BEGIN CERTIFICATE-----...", + "key": "-----BEGIN PRIVATE KEY-----...", + "certinfo": { + "issuer": "CA Name", + "subject": "CN=example.com", + "notBefore": "2024-01-01T00:00:00Z", + "notAfter": "2025-01-01T00:00:00Z", + "serialNumber": "123456" + } + } +] +``` + +### POST /api/certs/create +Create a new SSL certificate. + +**Request Body:** +```json +{ + "commonname": "example.com", + "organizationname": ["Your Organization"], + "organizationunit": ["IT Department"], + "dns": ["example.com", "www.example.com"], + "password": "ca-private-key-password" +} +``` + +**Response:** +```json +{ + "status": "success", + "message": "Certificate created successfully" +} +``` + +### POST /api/certs/delete +Delete an existing certificate. + +**Request Body:** +```json +{ + "domain": "example.com" +} +``` + +## Usage + +1. Start the server: +```bash +./scm +``` + +2. Create a certificate: +```bash +curl -X POST http://localhost:8777/api/certs/create \ + -H "Content-Type: application/json" \ + -d '{ + "commonname": "example.com", + "organizationname": ["My Company"], + "organizationunit": ["IT"], + "dns": ["example.com", "www.example.com"], + "password": "your-ca-key-password" + }' +``` + +3. List certificates: +```bash +curl http://localhost:8777/api/certs +``` + +4. Delete a certificate: +```bash +curl -X POST http://localhost:8777/api/certs/delete \ + -H "Content-Type: application/json" \ + -d '{"domain": "example.com"}' +``` + +## Development + +### Dependencies + +- `github.com/google/uuid` - UUID generation +- `github.com/joho/godotenv` - Environment variable loading +- `github.com/youmark/pkcs8` - PKCS#8 key handling +- `golang.org/x/crypto` - Cryptographic operations + +### Running in Development + +```bash +# Install dependencies +go mod tidy + +# Run the application +go run main.go + +# Or build and run +go build -o scm && ./scm +``` + +### Testing + +```bash +# Run tests +go test ./... + +# Run tests with verbose output +go test -v ./... +``` + +## Security Considerations + +- Store CA private keys securely and use strong passwords +- Implement proper access controls for the API endpoints +- Use HTTPS in production environments +- Regularly rotate certificates and CA keys +- Validate input data to prevent injection attacks +- Monitor certificate expiration dates + +## File Organization + +Certificates are stored in the following structure: +``` +CERTS_PATH/ +├── root/ +│ ├── root.crt # Root CA certificate +│ └── root.key # Root CA private key +├── example.com/ +│ ├── example.com.crt # Domain certificate +│ └── example.com.key # Domain private key +└── another-domain.com/ + ├── another-domain.com.crt + └── another-domain.com.key +``` + +## Troubleshooting + +### Common Issues + +1. **"Certificate not found"** - Ensure the CERTS_PATH is correctly configured +2. **"Invalid CA password"** - Verify the CA private key password +3. **"Permission denied"** - Check file system permissions for certificate directories +4. **"Port already in use"** - Change the SERVER_PORT in configuration + +### Logs + +The application logs to stdout. For production, consider redirecting logs to a file: +```bash +./scm >> /var/log/scm.log 2>&1 +``` + +## Contributing + +1. Fork the repository +2. Create a feature branch +3. Make your changes +4. Add tests for new functionality +5. Submit a pull request + +## License + +This project is licensed under the MIT License. See LICENSE file for details. diff --git a/api/CreateCert.go b/api/CreateCert.go index c7e23eb..89aaabc 100644 --- a/api/CreateCert.go +++ b/api/CreateCert.go @@ -27,13 +27,13 @@ func CreateCert(w http.ResponseWriter, r *http.Request) { "%s/%s/%s.crt", os.Getenv("CERTS_PATH"), "root", - "TolaMironcenkoCA", + "root", ), fmt.Sprintf( "%s/%s/%s.key", os.Getenv("CERTS_PATH"), "root", - "TolaMironcenkoCA", + "root", ), requestData.CAKeyPassword, )