feat(cert-manager): alle Ausgabeformate, Konvertieren, Bundle und PFX

- build liefert jeden Inhalt in jedem Format: Einzelzertifikat (PEM, DER, PKCS#7 .p7b/.p7c), Fullchain und Nur Kette auch als PKCS#7, Zertifikat und Schlüssel in einer PEM-Datei, PFX, Schlüssel (PKCS#8, klassisch, DER, optional mit Passwort) und CSR (PEM, DER)
- PKCS#7 von Hand aus ASN.1 gebaut, jedes Zertifikat mit seinen eigenen Bytes (RSA und EC)
- PFX schreiben für RSA und EC über einen begrenzten, im finally zurückgesetzten forge-Austausch; Kompatibel (3DES/SHA-1, Vorgabe) oder Modern (AES-256)
- Schlüssel und Passwörter nur in der Anfrage, nie in Antwort, Fehlertext oder Log; falscher Schlüssel: keyMismatch, kein Schlüssel: keyMissing, ohne Passwort: passwordRequired
- Reiter Konvertieren für Zertifikat, Schlüssel und Anfrage; Zusammenführen mit Kettenformat, Zertifikat und Schlüssel sowie PFX (Passwort doppelt, Verschlüsselung wählbar)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-10-09 15:46:43 +02:00
parent fcac0a3bfd
commit 65a1dca80f
18 changed files with 1877 additions and 47 deletions
+51 -2
View File
@@ -1256,7 +1256,8 @@
"filesWithCount": "Files ({count})",
"analyze": "Analyze",
"split": "Split",
"merge": "Merge"
"merge": "Merge",
"convert": "Convert"
},
"roles": {
"end-entity": "Server certificate",
@@ -1398,7 +1399,21 @@
"downloadFullchain": "Download fullchain",
"downloadChain": "Download chain only",
"busy": "Creating …",
"chainNeedsIssuer": "An intermediate certificate is missing for “chain only”. Add it in the “Files” tab."
"chainNeedsIssuer": "An intermediate certificate is missing for “chain only”. Add it in the “Files” tab.",
"formatLabel": "Chain format",
"formats": {
"pem": "PEM (.pem)",
"p7b": "PKCS#7 (.p7b)",
"p7c": "PKCS#7, binary (.p7c)"
},
"bundleTitle": "Certificate and key",
"bundleHint": "A single PEM file with the server certificate, the intermediate certificates and the private key. Keep it safe.",
"downloadBundle": "Certificate and key (one PEM file)",
"bundleNeedsKey": "There is no matching private key yet. Add it in the “Files” tab.",
"pfxTitle": "PFX file",
"pfxIntro": "A password-protected file with certificates and key, as Windows, IIS and many devices expect it.",
"pfxNoKey": "Without a matching key the PFX file contains only the certificates.",
"downloadPfx": "Download PFX file"
},
"chain": {
"issuedBy": "Issued by {name}",
@@ -1411,6 +1426,40 @@
"passwordInput": {
"show": "Show password",
"hide": "Hide password"
},
"pfx": {
"password": "PFX password",
"repeat": "Repeat password",
"mismatch": "The two passwords do not match.",
"encryption": "Encryption",
"compat": "Compatible (also older Windows servers)",
"modern": "Modern (AES-256)",
"modernHint": "Older Windows servers, such as Windows Server 2016, often cannot open the modern encryption. When in doubt, choose “Compatible”."
},
"convert": {
"intro": "Convert a single item of your files into another format.",
"nothingFound": "Nothing has been recognised yet that could be converted.",
"item": "What should be converted?",
"format": "Target format",
"groupCertificates": "Certificates",
"groupKeys": "Private keys",
"groupCsrs": "Certificate requests",
"formats": {
"certPem": "PEM (.crt)",
"certDer": "DER (.cer)",
"p7b": "PKCS#7 (.p7b)",
"p7c": "PKCS#7, binary (.p7c)",
"pkcs8": "PKCS#8 (.key)",
"traditional": "Traditional (PKCS#1 for RSA, SEC1 for EC)",
"pkcs8Der": "PKCS#8, binary (.key.der)",
"csrPem": "PEM (.csr)",
"csrDer": "DER (.csr.der)"
},
"keyNote": "The key is sent to Tessera only for the conversion and is not stored anywhere.",
"protectKey": "Protect the key with a password",
"keyPassword": "Password for the key",
"download": "Download",
"busy": "Creating …"
}
},
"tenderRadar": {