# Quick Task 261009-ikt: Cert Manager Umbau: mehrere Dateien, ZIP, Fullchain, alle Formate - Context **Gathered:** 2026-10-09 **Status:** Ready for planning ## Task Boundary Rework module "Zertifikat-Manager" (slug cert-manager; api `apps/api/src/cert-manager/`, web `apps/web/src/app/(portal)/modules/cert-manager/`). Source of the request: `.planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md` (user test 09.10.): 1. Bug: merging accepts only ONE file — selecting a second overwrites the first. 2. Upload of a ZIP (as delivered by a certificate vendor) — Tessera unpacks and analyses contained certificates/keys. 3. Choose what you want as output, e.g. "Fullchain" — Tessera orders server cert → intermediates (→ root optional) itself and offers the result for download. All common formats as input AND output (user decision 09.10., locked): PEM/CRT/CER (Base64), DER, PKCS#7 (.p7b/.p7c), PKCS#12 (.pfx/.p12 with password), private keys (PKCS#1, PKCS#8, encrypted/ unencrypted, RSA + EC), CSR; outputs: Fullchain, chain only (intermediates), single certificate, certificate + key (PEM bundle), PFX with chosen password. Module version + module changelog + guides are part of the task. ## Implementation Decisions ### Flow / structure - ONE upload tab (first tab) where the user drops/selects multiple files and/or ZIPs (and may paste PEM text). Everything uploaded forms a shared working set (list of files with remove buttons and what was recognised in each). The other tabs (Analysieren, Aufteilen, Zusammenführen/Fullchain, Konvertieren, Vorlagen) work on that shared set instead of having their own upload fields. Users' words: "in einem Reiter die ZIP bzw. die Einzelzertifikate hochladen und die einzelnen Reiter verarbeiten diese dann". ### Root certificate in Fullchain - Selectable, default WITHOUT root ("Root-Zertifikat mitnehmen" checkbox). ### Missing intermediate - Tessera reports the gap clearly ("Zwischenzertifikat fehlt") and offers a button "Fehlendes Zertifikat holen" which fetches it from the certificate's AIA caIssuers URL — ONLY on button press, never automatically. Fetch must be SSRF-safe (http/https only, public addresses only — reuse the project's existing `isPublicHttpUrl`/SSRF guard pattern, size and time limits, no redirects to private targets) and the result marked as "nachgeladen". ### Templates for target systems - Yes: one-click templates, e.g. Nginx, Apache, Windows/IIS (PFX), Nginx Proxy Manager (and other common ones at Claude's discretion, e.g. HAProxy combined PEM, Java keystore only if feasible without native tools — otherwise skip). Free selection of content + format remains available. ### Claude's Discretion - Where the working set lives (prefer browser memory only, never persisted server-side; private keys and passwords never stored or logged); ZIP limits (size, file count, nesting, zip-bomb ratio); key-to-certificate matching display; how CSRs are shown; file naming of downloads; whether the server or browser does the crypto (follow the existing module architecture); exact tab names. ## Specific Ideas - Chain building via Issuer/Subject + Authority/Subject Key Identifier; clear gap messages; verify the private key matches the certificate. - Existing module already analyses correctly (user: "Die Analyse funktioniert bereits richtig") — keep that behaviour, check existing conversion functions and close gaps. - Current module version 1.1.0 — check the module-changelog rule in docs/anleitung-entwicklung.md ("Höchstens ein Sprung je Modul zwischen zwei Tessera-Freigaben"; last release v1.10.1 on 2026-10-06) to decide bump vs. extending an unreleased entry. ## Canonical References - .planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md - docs/anleitung-entwicklung.md (module changelog rules) - docs/anleitung-anwender.md section "Zertifikat-Manager"