# Phase 9 Context: Cert Manager Module **Date:** 2026-07-01 **Status:** Ready for planning --- ## Certificate management toolkit module. Users upload or paste certificates, inspect parsed details, split fullchain/bundle files into individual certs, merge certs into chains or PFX bundles, and convert between formats. All processing server-side, fully ephemeral (no database storage). --- ## ### Processing & Persistence - **Server-side API** — All crypto operations happen in the NestJS backend, not client-side JavaScript - **Ephemeral** — No Prisma schema changes, no DB tables, no file storage. Upload → process → return result/download - Files are held in memory during request only (multer `memoryStorage`) ### Operations - **Inspect** — Parse any cert and return: subject, issuer, validity dates, SANs, key type/size, fingerprint (SHA-1 + SHA-256), serial, signature algorithm - **Split** — Accept fullchain.pem or P7B bundle; return array of individual certs (each downloadable as .crt/.pem) - **Merge** — Combine multiple certs into: - PEM chain (concatenated) - PFX/PKCS12 bundle (cert + optional private key, with password) - **Convert** — Between: PEM ↔ DER ↔ PFX/P12 ↔ P7B ↔ CRT/CER ### Input Modes - **File upload** — All formats: `.pem`, `.crt`, `.cer`, `.der`, `.pfx`, `.p12`, `.p7b`, `.p7c` - **Text paste** — PEM/CRT content pasted directly into textarea (auto-detected via `-----BEGIN` header) - **Password field** — Shown conditionally when format is PFX/P12 (both for reading and creating) ### Supported Formats | Format | Read | Write | |--------|------|-------| | PEM (.pem, .crt, .cer) | ✓ | ✓ | | DER (.der, .cer binary) | ✓ | ✓ | | PFX/PKCS12 (.pfx, .p12) | ✓ with password | ✓ with password | | P7B/PKCS7 (.p7b, .p7c) | ✓ | ✓ | ### Library - **`node-forge`** — Battle-tested Node.js crypto library; handles PEM, DER, PFX/PKCS12, P7B/PKCS7 in one package. No native bindings needed (pure JS, Docker-friendly). ### Module Registry - **Slug:** `cert-manager` - **Category:** `security-tools` - **Pattern:** Same as Domaincheck — `OnModuleInit` seed, `@UseModule('cert-manager')` guard ### UI Layout - Tab-based: **Analysieren** | **Aufteilen** | **Zusammenführen** | **Konvertieren** - Shared file drop zone + text area at top, tabs below for operation selection - Password field appears conditionally (PFX/P12 detected or PFX output selected) - Results shown inline with download buttons per cert ### API Endpoints All under `/modules/cert-manager`: - `POST /parse` — inspect single cert (multipart or JSON with PEM text) - `POST /split` — split fullchain/P7B → array of certs - `POST /merge` — merge certs → PEM chain or PFX - `POST /convert` — convert format ### Frontend Path - `apps/web/src/app/(portal)/modules/cert-manager/page.tsx` - `apps/web/src/app/(portal)/modules/cert-manager/actions.ts` --- ## - `.planning/ROADMAP.md` — Phase 9 definition, requirements CERT-01 through CERT-06 - `apps/api/src/domaincheck/` — Module pattern to follow (controller, seed, guard usage) - `apps/web/src/app/(portal)/modules/domaincheck/` — Frontend module pattern - `apps/api/src/module-registry/` — Registry service + UseModule guard --- ## ### Reusable Patterns - **NestJS module registration:** `domaincheck.module.ts` → `OnModuleInit` + `seedModule()` - **Module guard:** `@UseModule('slug')` from `module-registry/module.guard` - **File upload:** Use `@nestjs/platform-express` multer with `memoryStorage` (no disk writes) - **Frontend actions:** `actions.ts` with `'use server'` calling `/api-proxy/modules/[slug]/[endpoint]` - **Frontend page:** Client component with `useTranslations`, Card layout (`rounded-lg border border-border bg-card`) ### No Prisma Changes Phase adds zero new database tables. `node-forge` runs entirely in memory. ### Dependencies to Add - API: `node-forge` + `@types/node-forge` - No new frontend deps (file input + fetch already available) --- ## - Certificate expiry monitoring / alerts (would need DB + cron — separate phase) - Certificate store / saved cert library (needs DB — separate phase) - OCSP / CRL revocation check (nice to have, out of scope here) - Private key generation (out of scope — cert manager, not CA)