wt e6526fb780
Build / Build (push) Successful in 19s
added createrootcertificateifnotexists
2025-07-21 22:11:04 +07:00
2025-07-18 21:41:36 +07:00
2025-07-21 16:36:28 +07:00
2025-07-15 00:42:59 +07:00
2025-07-16 14:12:27 +07:00
2025-07-16 14:29:03 +07:00
2025-07-21 16:36:28 +07:00

SCM - SSL Certificate Manager

A Go-based SSL Certificate Manager that provides a REST API for managing SSL certificates. The system allows you to create, view, and delete SSL certificates signed by a Certificate Authority (CA).

Features

  • Certificate Management: Create, list, and delete SSL certificates
  • CA Integration: Uses a root Certificate Authority to sign certificates
  • REST API: Simple HTTP endpoints for certificate operations
  • TLS Support: Configurable HTTPS server with certificate validation
  • Certificate Parsing: Detailed certificate information extraction
  • File System Storage: Organized certificate storage in directories

Project Structure

scm/
├── api/                    # HTTP handlers and API endpoints
│   ├── Certs.go           # List certificates endpoint
│   ├── CreateCert.go      # Create certificate endpoint
│   ├── DeleteCert.go      # Delete certificate endpoint
│   ├── Spa.go             # Single-page application handler
│   └── frontend/          # Frontend assets
├── model/                 # Data structures and models
│   ├── CreateCertRequest.go
│   └── DeleteCertRequest.go
├── server/                # Server configuration and setup
├── utils/                 # Utility functions
│   ├── CheckExistsOrCreateDir.go
│   ├── CreateServerCert.go
│   ├── LoadEnv.go
│   ├── LoadRootCertAndKey.go
│   ├── ParseCert.go
│   └── SavePEMFile.go
├── main.go               # Application entry point
├── go.mod               # Go module definition
└── scm.conf            # Configuration file

Requirements

  • Go 1.24.5 or higher
  • Root Certificate Authority (CA) certificate and private key
  • Linux/Unix environment (recommended)

Installation

  1. Clone the repository:
git clone <repository-url>
cd scm
  1. Install dependencies:
go mod tidy
  1. Build the application:
go build -o scm

Configuration

Create a configuration file scm.conf in the project root:

# TLS Configuration
ENABLE_TLS=true
CERT_FILE=/path/to/server/certificate.crt
KEY_FILE=/path/to/server/private.key

# Certificate Storage
CERTS_PATH=/path/to/certificates/directory

# Server Configuration
SERVER_ADDRESS=0.0.0.0
SERVER_PORT=8777

Configuration Parameters

Parameter Description Default Required
ENABLE_TLS Enable HTTPS server false No
CERT_FILE Path to server certificate - If TLS enabled
KEY_FILE Path to server private key - If TLS enabled
CERTS_PATH Directory for certificate storage - Yes
SERVER_ADDRESS Server bind address 0.0.0.0 No
SERVER_PORT Server port 8080 No

Certificate Authority Setup

Before using the certificate manager, you need to set up a root CA:

  1. Create a root CA directory:
mkdir -p /path/to/certificates/root
  1. Place your root CA certificate and private key:
# Certificate: /path/to/certificates/root/root.crt
# Private Key: /path/to/certificates/root/root.key

API Endpoints

GET /api/certs

List all managed certificates with details.

Response:

[
  {
    "id": "uuid-string",
    "domain": "example.com",
    "href": "https://example.com",
    "cert": "-----BEGIN CERTIFICATE-----...",
    "key": "-----BEGIN PRIVATE KEY-----...",
    "certinfo": {
      "issuer": "CA Name",
      "subject": "CN=example.com",
      "notBefore": "2024-01-01T00:00:00Z",
      "notAfter": "2025-01-01T00:00:00Z",
      "serialNumber": "123456"
    }
  }
]

POST /api/certs/create

Create a new SSL certificate.

Request Body:

{
  "commonname": "example.com",
  "organizationname": ["Your Organization"],
  "organizationunit": ["IT Department"],
  "dns": ["example.com", "www.example.com"],
  "password": "ca-private-key-password"
}

Response:

{
  "status": "success",
  "message": "Certificate created successfully"
}

POST /api/certs/delete

Delete an existing certificate.

Request Body:

{
  "domain": "example.com"
}

Usage

  1. Start the server:
./scm
  1. Create a certificate:
curl -X POST http://localhost:8777/api/certs/create \
  -H "Content-Type: application/json" \
  -d '{
    "commonname": "example.com",
    "organizationname": ["My Company"],
    "organizationunit": ["IT"],
    "dns": ["example.com", "www.example.com"],
    "password": "your-ca-key-password"
  }'
  1. List certificates:
curl http://localhost:8777/api/certs
  1. Delete a certificate:
curl -X POST http://localhost:8777/api/certs/delete \
  -H "Content-Type: application/json" \
  -d '{"domain": "example.com"}'

Development

Dependencies

  • github.com/google/uuid - UUID generation
  • github.com/joho/godotenv - Environment variable loading
  • github.com/youmark/pkcs8 - PKCS#8 key handling
  • golang.org/x/crypto - Cryptographic operations

Running in Development

# Install dependencies
go mod tidy

# Run the application
go run main.go

# Or build and run
go build -o scm && ./scm

Testing

# Run tests
go test ./...

# Run tests with verbose output
go test -v ./...

Security Considerations

  • Store CA private keys securely and use strong passwords
  • Implement proper access controls for the API endpoints
  • Use HTTPS in production environments
  • Regularly rotate certificates and CA keys
  • Validate input data to prevent injection attacks
  • Monitor certificate expiration dates

File Organization

Certificates are stored in the following structure:

CERTS_PATH/
├── root/
│   ├── root.crt    # Root CA certificate
│   └── root.key    # Root CA private key
├── example.com/
│   ├── example.com.crt         # Domain certificate
│   └── example.com.key         # Domain private key
└── another-domain.com/
    ├── another-domain.com.crt
    └── another-domain.com.key

Troubleshooting

Common Issues

  1. "Certificate not found" - Ensure the CERTS_PATH is correctly configured
  2. "Invalid CA password" - Verify the CA private key password
  3. "Permission denied" - Check file system permissions for certificate directories
  4. "Port already in use" - Change the SERVER_PORT in configuration

Logs

The application logs to stdout. For production, consider redirecting logs to a file:

./scm >> /var/log/scm.log 2>&1

Contributing

  1. Fork the repository
  2. Create a feature branch
  3. Make your changes
  4. Add tests for new functionality
  5. Submit a pull request

License

This project is licensed under the MIT License. See LICENSE file for details.

S
Description
SSL Certificate manager
Readme MIT
360 KiB
Languages
HTML 43.3%
Go 34.8%
JavaScript 20%
Shell 1.1%
Dockerfile 0.8%