10 KiB
SCM - SSL Certificate Manager
A Go-based SSL Certificate Manager that provides a REST API for managing SSL certificates and Certificate Authority (CA) operations. The system allows you to create root certificates, manage SSL certificates, and perform certificate operations through a web interface.
Features
- Root CA Management: Create and manage root Certificate Authority certificates
- Certificate Management: Create, list, and delete SSL certificates
- CA Integration: Uses a root Certificate Authority to sign certificates
- REST API: Simple HTTP endpoints for certificate operations
- Web Interface: Frontend for certificate management operations
- TLS Support: Configurable HTTPS server with certificate validation
- Certificate Parsing: Detailed certificate information extraction
- File System Storage: Organized certificate storage in directories
Project Structure
scm/
├── api/ # HTTP handlers and API endpoints
│ ├── Certs.go # List certificates endpoint
│ ├── CreateCert.go # Create certificate endpoint
│ ├── DeleteCert.go # Delete certificate endpoint
│ ├── RootCert.go # Root certificate management endpoint
│ ├── Spa.go # Single-page application handler
│ └── frontend/ # Frontend assets
│ ├── css/ # Stylesheets
│ ├── js/ # JavaScript files
│ └── index.html # Main web interface
├── crt/ # Certificate operations and utilities
│ ├── CreateRootKeyCertificate.go # Root CA creation
│ ├── CreateServerCert.go # Server certificate creation
│ ├── LoadRootCertAndKey.go # CA certificate loading
│ ├── ParseCert.go # Certificate parsing utilities
│ └── SavePEMFile.go # PEM file operations
├── model/ # Data structures and models
│ ├── CreateCertRequest.go # Server certificate request model
│ ├── CreateRootCertRequest.go # Root certificate request model
│ └── DeleteCertRequest.go # Certificate deletion model
├── server/ # Server configuration and setup
├── utils/ # General utility functions
│ ├── CheckExistsOrCreateDir.go # Directory operations
│ └── LoadEnv.go # Environment loading
├── main.go # Application entry point
├── go.mod # Go module definition
├── go.sum # Go module checksums
└── scm.conf # Configuration file
Requirements
- Go 1.24.5 or higher
- Linux/Unix environment (recommended)
Installation
- Clone the repository:
git clone <repository-url>
cd scm
- Install dependencies:
go mod tidy
- Build the application:
go build -o scm
Configuration
Create a configuration file scm.conf in the project root:
# TLS Configuration
ENABLE_TLS=true
CERT_FILE=/path/to/server/certificate.crt
KEY_FILE=/path/to/server/private.key
# Certificate Storage
CERTS_PATH=/path/to/certificates/directory
# Server Configuration
SERVER_ADDRESS=0.0.0.0
SERVER_PORT=8777
Configuration Parameters
| Parameter | Description | Default | Required |
|---|---|---|---|
ENABLE_TLS |
Enable HTTPS server | false |
No |
CERT_FILE |
Path to server certificate | - | If TLS enabled |
KEY_FILE |
Path to server private key | - | If TLS enabled |
CERTS_PATH |
Directory for certificate storage | - | Yes |
SERVER_ADDRESS |
Server bind address | 0.0.0.0 |
No |
SERVER_PORT |
Server port | 8080 |
No |
API Endpoints
GET /api/certs/root
Check if root certificate exists.
Response:
{
"status": "ok"
}
POST /api/certs/root
Create a new root Certificate Authority certificate.
Request Body:
{
"CommonName": "My Root CA",
"Organization": ["My Organization"],
"OrganizationalUnit": ["IT Department"],
"Country": ["US"],
"Locality": ["City"],
"Province": ["State"],
"StreetAddress": ["123 Main St"],
"PostalCode": ["12345"],
"ValidityYears": 10,
"KeyPassword": "secure-password"
}
Response:
{
"status": "ok"
}
GET /api/certs
List all managed certificates with details.
Response:
[
{
"id": "uuid-string",
"domain": "example.com",
"href": "https://example.com",
"cert": "-----BEGIN CERTIFICATE-----...",
"key": "-----BEGIN PRIVATE KEY-----...",
"certinfo": {
"issuer": "CA Name",
"subject": "CN=example.com",
"notBefore": "2024-01-01T00:00:00Z",
"notAfter": "2025-01-01T00:00:00Z",
"serialNumber": "123456"
}
}
]
POST /api/certs/create
Create a new SSL certificate signed by the root CA.
Request Body:
{
"commonname": "example.com",
"organizationname": ["Your Organization"],
"organizationunit": ["IT Department"],
"dns": ["example.com", "www.example.com"],
"password": "ca-private-key-password"
}
Response:
{
"status": "success",
"message": "Certificate created successfully"
}
POST /api/certs/delete
Delete an existing certificate.
Request Body:
{
"domain": "example.com"
}
GET /
Access the web interface for certificate management.
Usage
Starting the Server
- Start the server:
./scm
- Access the web interface at
http://localhost:8777(or your configured address/port)
Creating Root Certificate Authority
Before creating server certificates, you need to create a root CA:
curl -X POST http://localhost:8777/api/rootcert \
-H "Content-Type: application/json" \
-d '{
"CommonName": "My Root CA",
"Organization": ["My Company"],
"OrganizationalUnit": ["IT"],
"Country": ["US"],
"ValidityYears": 10,
"KeyPassword": "secure-ca-password"
}'
Managing Server Certificates
- Create a certificate:
curl -X POST http://localhost:8777/api/certs/create \
-H "Content-Type: application/json" \
-d '{
"commonname": "example.com",
"organizationname": ["My Company"],
"organizationunit": ["IT"],
"dns": ["example.com", "www.example.com"],
"password": "your-ca-key-password"
}'
- List certificates:
curl http://localhost:8777/api/certs
- Delete a certificate:
curl -X POST http://localhost:8777/api/certs/delete \
-H "Content-Type: application/json" \
-d '{"domain": "example.com"}'
Development
Dependencies
github.com/google/uuid- UUID generation for certificatesgithub.com/joho/godotenv- Environment variable loadinggithub.com/youmark/pkcs8- PKCS#8 key handling and encryptiongolang.org/x/crypto- Cryptographic operations
Running in Development
# Install dependencies
go mod tidy
# Run the application
go run main.go
# Or build and run
go build -o scm && ./scm
Testing
# Run tests
go test ./...
# Run tests with verbose output
go test -v ./...
Security Considerations
- Root CA Security: Store CA private keys securely and use strong passwords
- Access Control: Implement proper access controls for API endpoints
- HTTPS: Use HTTPS in production environments
- Key Rotation: Regularly rotate certificates and CA keys
- Input Validation: Validate input data to prevent injection attacks
- Monitoring: Monitor certificate expiration dates
- Password Strength: Use strong passwords for CA key encryption
File Organization
Certificates are stored in the following structure:
CERTS_PATH/
├── root/
│ ├── root.crt # Root CA certificate
│ └── root.key # Root CA private key (encrypted)
├── example.com/
│ ├── example.com.crt # Domain certificate
│ └── example.com.key # Domain private key
└── another-domain.com/
├── another-domain.com.crt
└── another-domain.com.key
Workflow
- Initial Setup: Configure the application and create certificates directory
- Create Root CA: Use
/api/rootcertendpoint to create a root Certificate Authority - Create Server Certificates: Use
/api/certs/createto generate server certificates signed by the CA - Manage Certificates: List, view, and delete certificates as needed
- Deploy Certificates: Use the generated certificates in your applications
Troubleshooting
Common Issues
- "Certificate not found" - Ensure the CERTS_PATH is correctly configured and accessible
- "Invalid CA password" - Verify the CA private key password is correct
- "Permission denied" - Check file system permissions for certificate directories
- "Port already in use" - Change the SERVER_PORT in configuration
- "Root certificate not found" - Create a root CA first using the
/api/rootcertendpoint
Debugging Tips
- Check application logs for detailed error messages
- Verify certificate directory permissions
- Ensure the configuration file is properly formatted
- Test API endpoints individually to isolate issues
Logs
The application logs to stdout. For production, consider redirecting logs to a file:
./scm >> /var/log/scm.log 2>&1
Web Interface
The application includes a web-based interface accessible at the root URL. The interface provides:
- Root CA creation and management
- Certificate creation with form validation
- Certificate listing and viewing
- Certificate deletion
- Real-time status updates
Contributing
- Fork the repository
- Create a feature branch
- Make your changes
- Add tests for new functionality
- Ensure code follows Go best practices
- Submit a pull request
License
This project is licensed under the MIT License. See LICENSE file for details.
Version History
- Latest: Added root certificate management, web interface, and improved project structure
- Previous: Basic certificate management with REST API