Files
tessera-ctl/.planning/phases/09-cert-manager-module/09-CONTEXT.md
T
2026-07-01 15:39:24 +02:00

4.3 KiB

Phase 9 Context: Cert Manager Module

Date: 2026-07-01 Status: Ready for planning


Certificate management toolkit module. Users upload or paste certificates, inspect parsed details, split fullchain/bundle files into individual certs, merge certs into chains or PFX bundles, and convert between formats. All processing server-side, fully ephemeral (no database storage).


Processing & Persistence

  • Server-side API — All crypto operations happen in the NestJS backend, not client-side JavaScript
  • Ephemeral — No Prisma schema changes, no DB tables, no file storage. Upload → process → return result/download
  • Files are held in memory during request only (multer memoryStorage)

Operations

  • Inspect — Parse any cert and return: subject, issuer, validity dates, SANs, key type/size, fingerprint (SHA-1 + SHA-256), serial, signature algorithm
  • Split — Accept fullchain.pem or P7B bundle; return array of individual certs (each downloadable as .crt/.pem)
  • Merge — Combine multiple certs into:
    • PEM chain (concatenated)
    • PFX/PKCS12 bundle (cert + optional private key, with password)
  • Convert — Between: PEM ↔ DER ↔ PFX/P12 ↔ P7B ↔ CRT/CER

Input Modes

  • File upload — All formats: .pem, .crt, .cer, .der, .pfx, .p12, .p7b, .p7c
  • Text paste — PEM/CRT content pasted directly into textarea (auto-detected via -----BEGIN header)
  • Password field — Shown conditionally when format is PFX/P12 (both for reading and creating)

Supported Formats

Format Read Write
PEM (.pem, .crt, .cer) ✓ ✓
DER (.der, .cer binary) ✓ ✓
PFX/PKCS12 (.pfx, .p12) ✓ with password ✓ with password
P7B/PKCS7 (.p7b, .p7c) ✓ ✓

Library

  • node-forge — Battle-tested Node.js crypto library; handles PEM, DER, PFX/PKCS12, P7B/PKCS7 in one package. No native bindings needed (pure JS, Docker-friendly).

Module Registry

  • Slug: cert-manager
  • Category: security-tools
  • Pattern: Same as Domaincheck — OnModuleInit seed, @UseModule('cert-manager') guard

UI Layout

  • Tab-based: Analysieren | Aufteilen | Zusammenführen | Konvertieren
  • Shared file drop zone + text area at top, tabs below for operation selection
  • Password field appears conditionally (PFX/P12 detected or PFX output selected)
  • Results shown inline with download buttons per cert

API Endpoints

All under /modules/cert-manager:

  • POST /parse — inspect single cert (multipart or JSON with PEM text)
  • POST /split — split fullchain/P7B → array of certs
  • POST /merge — merge certs → PEM chain or PFX
  • POST /convert — convert format

Frontend Path

  • apps/web/src/app/(portal)/modules/cert-manager/page.tsx
  • apps/web/src/app/(portal)/modules/cert-manager/actions.ts

<canonical_refs>

  • .planning/ROADMAP.md — Phase 9 definition, requirements CERT-01 through CERT-06
  • apps/api/src/domaincheck/ — Module pattern to follow (controller, seed, guard usage)
  • apps/web/src/app/(portal)/modules/domaincheck/ — Frontend module pattern
  • apps/api/src/module-registry/ — Registry service + UseModule guard </canonical_refs>

<code_context>

Reusable Patterns

  • NestJS module registration: domaincheck.module.ts → OnModuleInit + seedModule()
  • Module guard: @UseModule('slug') from module-registry/module.guard
  • File upload: Use @nestjs/platform-express multer with memoryStorage (no disk writes)
  • Frontend actions: actions.ts with 'use server' calling /api-proxy/modules/[slug]/[endpoint]
  • Frontend page: Client component with useTranslations, Card layout (rounded-lg border border-border bg-card)

No Prisma Changes

Phase adds zero new database tables. node-forge runs entirely in memory.

Dependencies to Add

  • API: node-forge + @types/node-forge
  • No new frontend deps (file input + fetch already available) </code_context>

  • Certificate expiry monitoring / alerts (would need DB + cron — separate phase)
  • Certificate store / saved cert library (needs DB — separate phase)
  • OCSP / CRL revocation check (nice to have, out of scope here)
  • Private key generation (out of scope — cert manager, not CA)