feat(cert-manager): Reiter „Dateien“ mit mehreren Dateien und ein Parser für RSA und EC – Durchstich

- Ein gemeinsamer Arbeitsbereich im Browser: jede Auswahl hängt an, eine zweite Datei ersetzt nie die erste
- Ein Parser (node:crypto) für RSA- und EC-Zertifikate als PEM, DER und TRUSTED CERTIFICATE, Rolle je Datei
- Neue Route analyze (mehrere Dateien, 30 x 5 MiB, zusammen 20 MiB); alte Routen, Service und Web-Reiter entfernt
- Test-PKI-Fixtures (RSA und EC, Ketten, Schlüssel, CSR, PFX) mit Erzeugungsskript

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-10-09 14:52:29 +02:00
parent e079c307e4
commit 75ea83fc01
84 changed files with 2906 additions and 5160 deletions
+56 -112
View File
@@ -1250,123 +1250,67 @@
},
"certManager": {
"title": "Certificate Manager",
"description": "Check certificate bundles and download them in any format; inspect, split, merge and convert single certificates.",
"description": "Collect, check and convert certificates, intermediate certificates, keys and requests into the format you need.",
"tabs": {
"overview": "Overview",
"inspect": "Inspect",
"split": "Split",
"merge": "Merge",
"convert": "Convert"
"files": "Files",
"filesWithCount": "Files ({count})"
},
"dropZone": {
"placeholder": "Drag file here or click to browse",
"formats": ".pem, .crt, .cer, .der, .pfx, .p12, .p7b, .p7c"
"roles": {
"end-entity": "Server certificate",
"intermediate": "Intermediate certificate",
"root": "Root certificate",
"privateKey": "Private key",
"csr": "Certificate request (CSR)"
},
"paste": {
"placeholder": "Paste PEM content (-----BEGIN ...)"
},
"password": {
"label": "Password (PFX/P12)"
},
"or": "or",
"actions": {
"inspect": "Inspect",
"split": "Split",
"merge": "Merge",
"convert": "Convert",
"download": "Download",
"downloadZip": "Download all as ZIP",
"processing": "Processing...",
"zipFilename": "certificates.zip"
},
"certRole": {
"root": "Root CA",
"intermediate": "Intermediate CA",
"end-entity": "Certificate"
},
"emptyState": {
"inspect": "No certificate loaded.",
"inspectBody": "Upload a file or paste PEM text.",
"split": "No file loaded.",
"splitBody": "Upload a fullchain or P7B file.",
"merge": "No certificates selected.",
"mergeBody": "Upload at least two files.",
"convert": "No file loaded.",
"convertBody": "Upload a file and select an output format."
},
"error": {
"generic": "Processing failed. Check the file format or password.",
"wrongPassword": "Wrong password. Could not decrypt the PFX/P12 file.",
"unknownFormat": "Unknown format. The file could not be recognized as a certificate."
},
"overview": {
"dropTitle": "Drop certificate files or a ZIP here, or click",
"dropHint": "Everything at once, as delivered by the issuer: .zip, .pem, .crt, .cer, .key, .csr, .pfx, .p12, .p7b",
"removeFile": "Remove {name}",
"reset": "Remove all",
"files": {
"dropTitle": "Drop files here or click",
"dropHint": "You can add several files one after another, each one stays in the list. Tessera recognises the content itself, the file extension does not matter.",
"limits": "Up to {maxFiles} files, at most {maxFile} MB per file and {maxTotal} MB in total.",
"memoryNote": "The files stay in this browser window only. Tessera stores none of them; after reloading or closing the page the list is empty.",
"empty": "No files yet. Add your certificates and you will see here what they contain.",
"listTitle": "Your files ({count})",
"remove": "Remove \"{name}\"",
"removeShort": "Remove",
"removeAll": "Remove all",
"analyzing": "Checking files …",
"error": "The files could not be checked. Please make sure they are certificate files.",
"locked": "Protected: {files}. Enter the password to read this content as well.",
"lockedNotNeeded": "{files} is password-protected. You do not need it: certificate and private key are already available as separate files and listed below. You can create a new PFX file with your own password at the server certificate.",
"lockedPassword": "Password of the protected file",
"unlock": "Unlock",
"unlockAnyway": "Open with password anyway",
"nothingFound": "No certificate, key or certificate request was found in the files.",
"ignored": "Not used (no certificate detected): {files}",
"type": {
"end-entity": "Server certificate",
"intermediate": "Intermediate certificate",
"root": "Root certificate",
"privateKey": "Private key",
"csr": "Certificate request (CSR)"
"checking": "Checking …",
"retry": "Try again",
"expired": "expired",
"rejectedTitle": "Not added:",
"rejected": {
"duplicate": "\"{name}\" is already in the list.",
"tooMany": "\"{name}\": the list is full with {max} files.",
"tooLarge": "\"{name}\" is larger than {size} MB.",
"totalTooLarge": "\"{name}\": together this would be more than {size} MB."
},
"explain": {
"end-entity": "The actual certificate for your domain – it goes on the web server.",
"intermediate": "Vouches for your server certificate towards the browser. Install it together with the server certificate (chain).",
"root": "Top-level certificate authority. Usually already present in browsers and operating systems.",
"privateKey": "The secret key for the server certificate. Needed on the server, but must never be shared.",
"csr": "The request used to order the certificate from the issuer. Only needed for a reissue."
},
"issuer": "Issued by",
"validity": "Valid",
"names": "Valid for",
"key": "Key",
"belongsTo": "Belongs to",
"source": "Found in",
"valid": "Valid",
"expired": "Expired",
"expiresSoon": "Expires in {days} days",
"keySecret": "Keep secret: whoever has this key can impersonate your website.",
"downloading": "Creating …",
"exportError": "This file could not be created.",
"format": {
"crt": "PEM (.crt)",
"cer": "DER (.cer)",
"fullchain": "With chain (.pem)",
"p7b": "PKCS#7 (.p7b)",
"pfx": "PFX (.pfx)",
"key": "PEM (.key)",
"key-rsa": "RSA PEM (.rsa.key)",
"key-der": "DER (.key.der)",
"csr": "PEM (.csr)",
"csr-der": "DER (.csr.der)"
},
"formatHint": {
"crt": "Text format, e.g. for Apache, Nginx and most devices",
"cer": "Binary format, e.g. for Windows and Java",
"fullchain": "Certificate and chain in one file, e.g. for Nginx",
"p7b": "Certificate and chain without key, e.g. for Windows/IIS",
"pfx": "Certificate, chain and key in one password-protected file, e.g. for Windows/IIS and Exchange",
"key": "Key in standard format (PKCS#8)",
"key-rsa": "Key in older RSA format (PKCS#1), for older software",
"key-der": "Key as binary file",
"csr": "Certificate request as text",
"csr-der": "Certificate request as binary file"
},
"pfxWithKey": "The PFX file contains certificate, chain and private key. Set a password – it is asked for when importing.",
"pfxWithoutKey": "No key is available for this certificate – the PFX file contains only certificate and chain. Set a password.",
"pfxPassword": "Password for the PFX file",
"pfxDownload": "Download PFX"
"ignored": {
"unknown": "No certificate was recognised in it.",
"nestedZip": "A ZIP inside a ZIP is not opened.",
"encryptedZip": "The ZIP content is password protected and is skipped.",
"brokenZip": "The ZIP cannot be read.",
"tooLarge": "The file is too large and is skipped.",
"suspicious": "The file is packed unusually tightly and is skipped.",
"zipTooLarge": "The ZIP contains too much data and is not opened.",
"tooManyEntries": "The ZIP contains too many files and is not opened.",
"unsupportedKey": "This key type is not supported."
}
},
"errors": {
"generic": "The files could not be checked. Please try again.",
"invalidInput": "The input is incomplete or invalid. Please check your entries.",
"notACertificate": "At least one entry is not a certificate. Please check the files.",
"noChain": "There is no chain to download. Add the intermediate certificate.",
"keyMissing": "This needs the matching private key. Add it in the \"Files\" tab.",
"keyMismatch": "The key does not belong to this certificate.",
"passwordRequired": "Please enter a password.",
"formatNotPossible": "This format is not possible for the key type. Choose another format.",
"templateNeedsKey": "This template needs the certificate and the matching private key.",
"tooLarge": "The files are too large together. Remove some files and try again.",
"aiaMissing": "The certificate names no address from which the missing certificate could be fetched.",
"aiaInternal": "The address in the certificate does not point to a public server and is not contacted.",
"aiaNotIssuer": "The address did not deliver a matching certificate of the issuer.",
"aiaUnreachable": "The issuer's server cannot be reached. Download the certificate yourself and add it.",
"aiaTooLarge": "The issuer's answer is too large and was discarded."
}
},
"tenderRadar": {