a32f5f948b
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
4.3 KiB
4.3 KiB
Phase 9 Context: Cert Manager Module
Date: 2026-07-01 Status: Ready for planning
Certificate management toolkit module. Users upload or paste certificates, inspect parsed details, split fullchain/bundle files into individual certs, merge certs into chains or PFX bundles, and convert between formats. All processing server-side, fully ephemeral (no database storage).
Processing & Persistence
- Server-side API — All crypto operations happen in the NestJS backend, not client-side JavaScript
- Ephemeral — No Prisma schema changes, no DB tables, no file storage. Upload → process → return result/download
- Files are held in memory during request only (multer
memoryStorage)
Operations
- Inspect — Parse any cert and return: subject, issuer, validity dates, SANs, key type/size, fingerprint (SHA-1 + SHA-256), serial, signature algorithm
- Split — Accept fullchain.pem or P7B bundle; return array of individual certs (each downloadable as .crt/.pem)
- Merge — Combine multiple certs into:
- PEM chain (concatenated)
- PFX/PKCS12 bundle (cert + optional private key, with password)
- Convert — Between: PEM ↔ DER ↔ PFX/P12 ↔ P7B ↔ CRT/CER
Input Modes
- File upload — All formats:
.pem,.crt,.cer,.der,.pfx,.p12,.p7b,.p7c - Text paste — PEM/CRT content pasted directly into textarea (auto-detected via
-----BEGINheader) - Password field — Shown conditionally when format is PFX/P12 (both for reading and creating)
Supported Formats
| Format | Read | Write |
|---|---|---|
| PEM (.pem, .crt, .cer) | ✓ | ✓ |
| DER (.der, .cer binary) | ✓ | ✓ |
| PFX/PKCS12 (.pfx, .p12) | ✓ with password | ✓ with password |
| P7B/PKCS7 (.p7b, .p7c) | ✓ | ✓ |
Library
node-forge— Battle-tested Node.js crypto library; handles PEM, DER, PFX/PKCS12, P7B/PKCS7 in one package. No native bindings needed (pure JS, Docker-friendly).
Module Registry
- Slug:
cert-manager - Category:
security-tools - Pattern: Same as Domaincheck —
OnModuleInitseed,@UseModule('cert-manager')guard
UI Layout
- Tab-based: Analysieren | Aufteilen | Zusammenführen | Konvertieren
- Shared file drop zone + text area at top, tabs below for operation selection
- Password field appears conditionally (PFX/P12 detected or PFX output selected)
- Results shown inline with download buttons per cert
API Endpoints
All under /modules/cert-manager:
POST /parse— inspect single cert (multipart or JSON with PEM text)POST /split— split fullchain/P7B → array of certsPOST /merge— merge certs → PEM chain or PFXPOST /convert— convert format
Frontend Path
apps/web/src/app/(portal)/modules/cert-manager/page.tsxapps/web/src/app/(portal)/modules/cert-manager/actions.ts
<canonical_refs>
.planning/ROADMAP.md— Phase 9 definition, requirements CERT-01 through CERT-06apps/api/src/domaincheck/— Module pattern to follow (controller, seed, guard usage)apps/web/src/app/(portal)/modules/domaincheck/— Frontend module patternapps/api/src/module-registry/— Registry service + UseModule guard </canonical_refs>
<code_context>
Reusable Patterns
- NestJS module registration:
domaincheck.module.ts→OnModuleInit+seedModule() - Module guard:
@UseModule('slug')frommodule-registry/module.guard - File upload: Use
@nestjs/platform-expressmulter withmemoryStorage(no disk writes) - Frontend actions:
actions.tswith'use server'calling/api-proxy/modules/[slug]/[endpoint] - Frontend page: Client component with
useTranslations, Card layout (rounded-lg border border-border bg-card)
No Prisma Changes
Phase adds zero new database tables. node-forge runs entirely in memory.
Dependencies to Add
- API:
node-forge+@types/node-forge - No new frontend deps (file input + fetch already available) </code_context>
- Certificate expiry monitoring / alerts (would need DB + cron — separate phase)
- Certificate store / saved cert library (needs DB — separate phase)
- OCSP / CRL revocation check (nice to have, out of scope here)
- Private key generation (out of scope — cert manager, not CA)