docs(09): add Phase 9 Cert Manager to roadmap + capture context
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
+22
-1
@@ -21,6 +21,7 @@ Decimal phases appear between their surrounding integers in numeric order.
|
|||||||
- [ ] **Phase 6: Desktop Client & CI/CD** - Tauri wrapper for Windows/Linux and automated Gitea integration
|
- [ ] **Phase 6: Desktop Client & CI/CD** - Tauri wrapper for Windows/Linux and automated Gitea integration
|
||||||
- [x] **Phase 7: DKV Fleet Module** - Automated DKV invoice processing via email monitoring, PDF parsing, and Excel export with driver mapping (completed 2026-06-27)
|
- [x] **Phase 7: DKV Fleet Module** - Automated DKV invoice processing via email monitoring, PDF parsing, and Excel export with driver mapping (completed 2026-06-27)
|
||||||
- [x] **Phase 8: Dashboard Widgets Vollimplementierung** - Calculator, Favorites, and Stopwatch widgets plus unified grid constraints across all dashboard widgets (completed 2026-07-01)
|
- [x] **Phase 8: Dashboard Widgets Vollimplementierung** - Calculator, Favorites, and Stopwatch widgets plus unified grid constraints across all dashboard widgets (completed 2026-07-01)
|
||||||
|
- [ ] **Phase 9: Cert Manager Module** - Server-side certificate toolkit: upload/paste, inspect, split chains, merge/bundle, convert formats, password-protected PFX support
|
||||||
|
|
||||||
## Phase Details
|
## Phase Details
|
||||||
|
|
||||||
@@ -278,10 +279,29 @@ Decimal phases appear between their surrounding integers in numeric order.
|
|||||||
|
|
||||||
**UI hint**: yes
|
**UI hint**: yes
|
||||||
|
|
||||||
|
### Phase 9: Cert Manager Module
|
||||||
|
|
||||||
|
**Goal:** Users can upload or paste certificates in any common format, inspect their details, split fullchain/P7B bundles into individual certificates, merge certs into chains or PFX bundles, and convert between formats — all processed server-side with no database persistence.
|
||||||
|
**Mode:** mvp
|
||||||
|
**Depends on**: Phase 3
|
||||||
|
**Requirements**: CERT-01, CERT-02, CERT-03, CERT-04, CERT-05, CERT-06
|
||||||
|
**Success Criteria** (what must be TRUE):
|
||||||
|
|
||||||
|
1. User can upload a cert file (PEM, DER, PFX/P12, CRT, CER, P7B) or paste PEM/CRT text and see parsed details (subject, issuer, validity, SANs, fingerprint)
|
||||||
|
2. User can split a fullchain.pem or P7B bundle into individual certificate files (downloadable)
|
||||||
|
3. User can merge multiple cert files into a PEM chain or a PFX bundle (with password)
|
||||||
|
4. User can convert between PEM, DER, PFX/P12, P7B, CRT/CER formats
|
||||||
|
5. Password-protected PFX/PKCS12 files can be opened (password prompt) and created (password input)
|
||||||
|
6. Module appears in the module registry with slug `cert-manager`
|
||||||
|
|
||||||
|
**Plans**: 0/0 plans created
|
||||||
|
|
||||||
|
**UI hint**: yes
|
||||||
|
|
||||||
## Progress
|
## Progress
|
||||||
|
|
||||||
**Execution Order:**
|
**Execution Order:**
|
||||||
Phases execute in numeric order: 1 -> 2 -> 3 -> 4 -> 5 -> 6 -> 7 -> 8
|
Phases execute in numeric order: 1 -> 2 -> 3 -> 4 -> 5 -> 6 -> 7 -> 8 -> 9
|
||||||
|
|
||||||
| Phase | Plans Complete | Status | Completed |
|
| Phase | Plans Complete | Status | Completed |
|
||||||
|-------|----------------|--------|-----------|
|
|-------|----------------|--------|-----------|
|
||||||
@@ -293,3 +313,4 @@ Phases execute in numeric order: 1 -> 2 -> 3 -> 4 -> 5 -> 6 -> 7 -> 8
|
|||||||
| 6. Desktop Client & CI/CD | 2/3 | In Progress| |
|
| 6. Desktop Client & CI/CD | 2/3 | In Progress| |
|
||||||
| 7. DKV Fleet Module | 6/6 | Complete | 2026-06-27 |
|
| 7. DKV Fleet Module | 6/6 | Complete | 2026-06-27 |
|
||||||
| 8. Dashboard Widgets Vollimplementierung | 4/4 | Complete | 2026-07-01 |
|
| 8. Dashboard Widgets Vollimplementierung | 4/4 | Complete | 2026-07-01 |
|
||||||
|
| 9. Cert Manager Module | 0/0 | Not started | - |
|
||||||
|
|||||||
@@ -0,0 +1,104 @@
|
|||||||
|
# Phase 9 Context: Cert Manager Module
|
||||||
|
|
||||||
|
**Date:** 2026-07-01
|
||||||
|
**Status:** Ready for planning
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## <domain>
|
||||||
|
Certificate management toolkit module. Users upload or paste certificates, inspect parsed details, split fullchain/bundle files into individual certs, merge certs into chains or PFX bundles, and convert between formats. All processing server-side, fully ephemeral (no database storage).
|
||||||
|
</domain>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## <decisions>
|
||||||
|
|
||||||
|
### Processing & Persistence
|
||||||
|
- **Server-side API** — All crypto operations happen in the NestJS backend, not client-side JavaScript
|
||||||
|
- **Ephemeral** — No Prisma schema changes, no DB tables, no file storage. Upload → process → return result/download
|
||||||
|
- Files are held in memory during request only (multer `memoryStorage`)
|
||||||
|
|
||||||
|
### Operations
|
||||||
|
- **Inspect** — Parse any cert and return: subject, issuer, validity dates, SANs, key type/size, fingerprint (SHA-1 + SHA-256), serial, signature algorithm
|
||||||
|
- **Split** — Accept fullchain.pem or P7B bundle; return array of individual certs (each downloadable as .crt/.pem)
|
||||||
|
- **Merge** — Combine multiple certs into:
|
||||||
|
- PEM chain (concatenated)
|
||||||
|
- PFX/PKCS12 bundle (cert + optional private key, with password)
|
||||||
|
- **Convert** — Between: PEM ↔ DER ↔ PFX/P12 ↔ P7B ↔ CRT/CER
|
||||||
|
|
||||||
|
### Input Modes
|
||||||
|
- **File upload** — All formats: `.pem`, `.crt`, `.cer`, `.der`, `.pfx`, `.p12`, `.p7b`, `.p7c`
|
||||||
|
- **Text paste** — PEM/CRT content pasted directly into textarea (auto-detected via `-----BEGIN` header)
|
||||||
|
- **Password field** — Shown conditionally when format is PFX/P12 (both for reading and creating)
|
||||||
|
|
||||||
|
### Supported Formats
|
||||||
|
| Format | Read | Write |
|
||||||
|
|--------|------|-------|
|
||||||
|
| PEM (.pem, .crt, .cer) | ✓ | ✓ |
|
||||||
|
| DER (.der, .cer binary) | ✓ | ✓ |
|
||||||
|
| PFX/PKCS12 (.pfx, .p12) | ✓ with password | ✓ with password |
|
||||||
|
| P7B/PKCS7 (.p7b, .p7c) | ✓ | ✓ |
|
||||||
|
|
||||||
|
### Library
|
||||||
|
- **`node-forge`** — Battle-tested Node.js crypto library; handles PEM, DER, PFX/PKCS12, P7B/PKCS7 in one package. No native bindings needed (pure JS, Docker-friendly).
|
||||||
|
|
||||||
|
### Module Registry
|
||||||
|
- **Slug:** `cert-manager`
|
||||||
|
- **Category:** `security-tools`
|
||||||
|
- **Pattern:** Same as Domaincheck — `OnModuleInit` seed, `@UseModule('cert-manager')` guard
|
||||||
|
|
||||||
|
### UI Layout
|
||||||
|
- Tab-based: **Analysieren** | **Aufteilen** | **Zusammenführen** | **Konvertieren**
|
||||||
|
- Shared file drop zone + text area at top, tabs below for operation selection
|
||||||
|
- Password field appears conditionally (PFX/P12 detected or PFX output selected)
|
||||||
|
- Results shown inline with download buttons per cert
|
||||||
|
|
||||||
|
### API Endpoints
|
||||||
|
All under `/modules/cert-manager`:
|
||||||
|
- `POST /parse` — inspect single cert (multipart or JSON with PEM text)
|
||||||
|
- `POST /split` — split fullchain/P7B → array of certs
|
||||||
|
- `POST /merge` — merge certs → PEM chain or PFX
|
||||||
|
- `POST /convert` — convert format
|
||||||
|
|
||||||
|
### Frontend Path
|
||||||
|
- `apps/web/src/app/(portal)/modules/cert-manager/page.tsx`
|
||||||
|
- `apps/web/src/app/(portal)/modules/cert-manager/actions.ts`
|
||||||
|
|
||||||
|
</decisions>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## <canonical_refs>
|
||||||
|
- `.planning/ROADMAP.md` — Phase 9 definition, requirements CERT-01 through CERT-06
|
||||||
|
- `apps/api/src/domaincheck/` — Module pattern to follow (controller, seed, guard usage)
|
||||||
|
- `apps/web/src/app/(portal)/modules/domaincheck/` — Frontend module pattern
|
||||||
|
- `apps/api/src/module-registry/` — Registry service + UseModule guard
|
||||||
|
</canonical_refs>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## <code_context>
|
||||||
|
|
||||||
|
### Reusable Patterns
|
||||||
|
- **NestJS module registration:** `domaincheck.module.ts` → `OnModuleInit` + `seedModule()`
|
||||||
|
- **Module guard:** `@UseModule('slug')` from `module-registry/module.guard`
|
||||||
|
- **File upload:** Use `@nestjs/platform-express` multer with `memoryStorage` (no disk writes)
|
||||||
|
- **Frontend actions:** `actions.ts` with `'use server'` calling `/api-proxy/modules/[slug]/[endpoint]`
|
||||||
|
- **Frontend page:** Client component with `useTranslations`, Card layout (`rounded-lg border border-border bg-card`)
|
||||||
|
|
||||||
|
### No Prisma Changes
|
||||||
|
Phase adds zero new database tables. `node-forge` runs entirely in memory.
|
||||||
|
|
||||||
|
### Dependencies to Add
|
||||||
|
- API: `node-forge` + `@types/node-forge`
|
||||||
|
- No new frontend deps (file input + fetch already available)
|
||||||
|
</code_context>
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## <deferred>
|
||||||
|
- Certificate expiry monitoring / alerts (would need DB + cron — separate phase)
|
||||||
|
- Certificate store / saved cert library (needs DB — separate phase)
|
||||||
|
- OCSP / CRL revocation check (nice to have, out of scope here)
|
||||||
|
- Private key generation (out of scope — cert manager, not CA)
|
||||||
|
</deferred>
|
||||||
Reference in New Issue
Block a user