feat(cert-manager): Zertifikatspaket hochladen, erkennen und in jedem Format herunterladen

Neuer erster Reiter Übersicht: mehrere Dateien oder die ZIP vom Aussteller
auf einmal ablegen. Der Server erkennt jedes Teil (Server-, Zwischen-,
Stammzertifikat, privater Schlüssel, CSR, auch aus PFX/P7B), fasst
Duplikate zusammen, ordnet Schlüssel/CSR dem Zertifikat zu und baut die
Kette. Unter jedem Teil stehen Download-Knöpfe für alle passenden Formate
(crt, cer, Fullchain, p7b, pfx mit Schlüssel und Kette; key PKCS#8/PKCS#1/
DER; csr PEM/DER). Geschützte PFX lassen sich mit Passwort entsperren.

Neue Endpunkte POST analyze (Dateien/ZIP, Begrenzung Anzahl und Größe vor
dem Entpacken) und POST export (JSON, zustandslos). Modultexte siezen jetzt
durchgehend; Gültigkeit in UTC wie im Zertifikat.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-10-01 15:23:34 +02:00
parent 645c5e5887
commit c07b0cfaf0
11 changed files with 1811 additions and 52 deletions
+74 -6
View File
@@ -1182,8 +1182,9 @@
},
"certManager": {
"title": "Zertifikat-Manager",
"description": "Zertifikate analysieren, aufteilen, zusammenführen und konvertieren.",
"description": "Zertifikatspakete prüfen und in jedes Format bringen; einzelne Zertifikate analysieren, aufteilen, zusammenführen und konvertieren.",
"tabs": {
"overview": "Übersicht",
"inspect": "Analysieren",
"split": "Aufteilen",
"merge": "Zusammenführen",
@@ -1217,18 +1218,85 @@
},
"emptyState": {
"inspect": "Kein Zertifikat geladen.",
"inspectBody": "Lade eine Datei hoch oder füge PEM-Text ein.",
"inspectBody": "Laden Sie eine Datei hoch oder fügen Sie PEM-Text ein.",
"split": "Keine Datei geladen.",
"splitBody": "Lade eine Fullchain- oder P7B-Datei hoch.",
"splitBody": "Laden Sie eine Fullchain- oder P7B-Datei hoch.",
"merge": "Keine Zertifikate ausgewählt.",
"mergeBody": "Lade mindestens zwei Dateien hoch.",
"mergeBody": "Laden Sie mindestens zwei Dateien hoch.",
"convert": "Keine Datei geladen.",
"convertBody": "Lade eine Datei hoch und wähle ein Ausgabeformat."
"convertBody": "Laden Sie eine Datei hoch und wählen Sie ein Ausgabeformat."
},
"error": {
"generic": "Verarbeitung fehlgeschlagen. Prüfe das Dateiformat oder das Passwort.",
"generic": "Verarbeitung fehlgeschlagen. Prüfen Sie das Dateiformat oder das Passwort.",
"wrongPassword": "Falsches Passwort. PFX/P12-Datei konnte nicht entschlüsselt werden.",
"unknownFormat": "Unbekanntes Format. Die Datei konnte nicht als Zertifikat erkannt werden."
},
"overview": {
"dropTitle": "Zertifikatsdateien oder ZIP hierher ziehen oder klicken",
"dropHint": "Alles auf einmal, so wie es vom Aussteller kommt: .zip, .pem, .crt, .cer, .key, .csr, .pfx, .p12, .p7b",
"removeFile": "{name} entfernen",
"reset": "Alle entfernen",
"analyzing": "Dateien werden geprüft …",
"error": "Die Dateien konnten nicht geprüft werden. Bitte prüfen Sie, ob es Zertifikatsdateien sind.",
"locked": "Geschützt: {files}. Geben Sie das Passwort ein, um auch diesen Inhalt zu lesen.",
"lockedPassword": "Passwort der geschützten Datei",
"unlock": "Entsperren",
"nothingFound": "In den Dateien wurde kein Zertifikat, Schlüssel und keine Zertifikatsanfrage gefunden.",
"ignored": "Nicht verwendet (kein Zertifikat erkannt): {files}",
"type": {
"end-entity": "Serverzertifikat",
"intermediate": "Zwischenzertifikat",
"root": "Stammzertifikat",
"privateKey": "Privater Schlüssel",
"csr": "Zertifikatsanfrage (CSR)"
},
"explain": {
"end-entity": "Das eigentliche Zertifikat für Ihre Domain – das gehört auf den Webserver.",
"intermediate": "Bestätigt Ihr Serverzertifikat gegenüber dem Browser. Wird zusammen mit dem Serverzertifikat eingespielt (Kette).",
"root": "Oberste Zertifizierungsstelle. Ist in Browsern und Betriebssystemen meist schon vorhanden.",
"privateKey": "Der geheime Schlüssel zum Serverzertifikat. Wird auf dem Server gebraucht, darf aber nie weitergegeben werden.",
"csr": "Die Anfrage, mit der das Zertifikat beim Aussteller bestellt wurde. Wird nur für eine Neuausstellung gebraucht."
},
"issuer": "Ausgestellt von",
"validity": "Gültig",
"names": "Gilt für",
"key": "Schlüssel",
"belongsTo": "Gehört zu",
"source": "Gefunden in",
"valid": "Gültig",
"expired": "Abgelaufen",
"expiresSoon": "Läuft in {days} Tagen ab",
"keySecret": "Geheim halten: Wer diesen Schlüssel hat, kann sich als Ihre Website ausgeben.",
"downloading": "Wird erstellt …",
"exportError": "Diese Datei konnte nicht erstellt werden.",
"format": {
"crt": "PEM (.crt)",
"cer": "DER (.cer)",
"fullchain": "Mit Kette (.pem)",
"p7b": "PKCS#7 (.p7b)",
"pfx": "PFX (.pfx)",
"key": "PEM (.key)",
"key-rsa": "RSA-PEM (.rsa.key)",
"key-der": "DER (.key.der)",
"csr": "PEM (.csr)",
"csr-der": "DER (.csr.der)"
},
"formatHint": {
"crt": "Textformat, z. B. für Apache, Nginx und die meisten Geräte",
"cer": "Binärformat, z. B. für Windows und Java",
"fullchain": "Zertifikat und Kette in einer Datei, z. B. für Nginx",
"p7b": "Zertifikat und Kette ohne Schlüssel, z. B. für Windows/IIS",
"pfx": "Zertifikat, Kette und Schlüssel in einer passwortgeschützten Datei, z. B. für Windows/IIS und Exchange",
"key": "Schlüssel im Standardformat (PKCS#8)",
"key-rsa": "Schlüssel im älteren RSA-Format (PKCS#1), für ältere Software",
"key-der": "Schlüssel als Binärdatei",
"csr": "Zertifikatsanfrage als Text",
"csr-der": "Zertifikatsanfrage als Binärdatei"
},
"pfxWithKey": "Die PFX-Datei enthält Zertifikat, Kette und privaten Schlüssel. Legen Sie ein Passwort fest – es wird beim Einspielen abgefragt.",
"pfxWithoutKey": "Zu diesem Zertifikat liegt kein Schlüssel vor – die PFX-Datei enthält nur Zertifikat und Kette. Legen Sie ein Passwort fest.",
"pfxPassword": "Passwort für die PFX-Datei",
"pfxDownload": "PFX herunterladen"
}
},
"tenderRadar": {
+69 -1
View File
@@ -1182,8 +1182,9 @@
},
"certManager": {
"title": "Certificate Manager",
"description": "Inspect, split, merge and convert certificates.",
"description": "Check certificate bundles and download them in any format; inspect, split, merge and convert single certificates.",
"tabs": {
"overview": "Overview",
"inspect": "Inspect",
"split": "Split",
"merge": "Merge",
@@ -1229,6 +1230,73 @@
"generic": "Processing failed. Check the file format or password.",
"wrongPassword": "Wrong password. Could not decrypt the PFX/P12 file.",
"unknownFormat": "Unknown format. The file could not be recognized as a certificate."
},
"overview": {
"dropTitle": "Drop certificate files or a ZIP here, or click",
"dropHint": "Everything at once, as delivered by the issuer: .zip, .pem, .crt, .cer, .key, .csr, .pfx, .p12, .p7b",
"removeFile": "Remove {name}",
"reset": "Remove all",
"analyzing": "Checking files …",
"error": "The files could not be checked. Please make sure they are certificate files.",
"locked": "Protected: {files}. Enter the password to read this content as well.",
"lockedPassword": "Password of the protected file",
"unlock": "Unlock",
"nothingFound": "No certificate, key or certificate request was found in the files.",
"ignored": "Not used (no certificate detected): {files}",
"type": {
"end-entity": "Server certificate",
"intermediate": "Intermediate certificate",
"root": "Root certificate",
"privateKey": "Private key",
"csr": "Certificate request (CSR)"
},
"explain": {
"end-entity": "The actual certificate for your domain – it goes on the web server.",
"intermediate": "Vouches for your server certificate towards the browser. Install it together with the server certificate (chain).",
"root": "Top-level certificate authority. Usually already present in browsers and operating systems.",
"privateKey": "The secret key for the server certificate. Needed on the server, but must never be shared.",
"csr": "The request used to order the certificate from the issuer. Only needed for a reissue."
},
"issuer": "Issued by",
"validity": "Valid",
"names": "Valid for",
"key": "Key",
"belongsTo": "Belongs to",
"source": "Found in",
"valid": "Valid",
"expired": "Expired",
"expiresSoon": "Expires in {days} days",
"keySecret": "Keep secret: whoever has this key can impersonate your website.",
"downloading": "Creating …",
"exportError": "This file could not be created.",
"format": {
"crt": "PEM (.crt)",
"cer": "DER (.cer)",
"fullchain": "With chain (.pem)",
"p7b": "PKCS#7 (.p7b)",
"pfx": "PFX (.pfx)",
"key": "PEM (.key)",
"key-rsa": "RSA PEM (.rsa.key)",
"key-der": "DER (.key.der)",
"csr": "PEM (.csr)",
"csr-der": "DER (.csr.der)"
},
"formatHint": {
"crt": "Text format, e.g. for Apache, Nginx and most devices",
"cer": "Binary format, e.g. for Windows and Java",
"fullchain": "Certificate and chain in one file, e.g. for Nginx",
"p7b": "Certificate and chain without key, e.g. for Windows/IIS",
"pfx": "Certificate, chain and key in one password-protected file, e.g. for Windows/IIS and Exchange",
"key": "Key in standard format (PKCS#8)",
"key-rsa": "Key in older RSA format (PKCS#1), for older software",
"key-der": "Key as binary file",
"csr": "Certificate request as text",
"csr-der": "Certificate request as binary file"
},
"pfxWithKey": "The PFX file contains certificate, chain and private key. Set a password – it is asked for when importing.",
"pfxWithoutKey": "No key is available for this certificate – the PFX file contains only certificate and chain. Set a password.",
"pfxPassword": "Password for the PFX file",
"pfxDownload": "Download PFX"
}
},
"tenderRadar": {
@@ -103,6 +103,13 @@ export const UMLAUT_REPLACEMENTS: Record<string, string> = {
* and must never be touched by the replacement or flagged by the guard.
*/
export const UMLAUT_ALLOWLIST: readonly string[] = [
// quick-261001-l4q: Zertifikatsmodul, Übersicht (korrektes Deutsch)
'Aussteller',
'Betriebssystemen',
'Neuausstellung',
'passwortgeschützten',
'Schlüssel',
'Zertifizierungsstelle',
// quick-260929-if2: „lässt“ (Erinnerung „lässt sich nicht mehr bearbeiten“)
'lässt',
'manuell',