Files
tessera-ctl/.planning/quick/261009-ikt-cert-manager-umbau-mehrere-dateien-zip-f/261009-ikt-CONTEXT.md
T
schalli 76a30458fc docs(quick-261009-ikt): Cert-Manager-Umbau
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-09 17:12:10 +02:00

4.0 KiB

Quick Task 261009-ikt: Cert Manager Umbau: mehrere Dateien, ZIP, Fullchain, alle Formate - Context

Gathered: 2026-10-09 Status: Ready for planning

## Task Boundary

Rework module "Zertifikat-Manager" (slug cert-manager; api apps/api/src/cert-manager/, web apps/web/src/app/(portal)/modules/cert-manager/). Source of the request: .planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md (user test 09.10.):

  1. Bug: merging accepts only ONE file — selecting a second overwrites the first.
  2. Upload of a ZIP (as delivered by a certificate vendor) — Tessera unpacks and analyses contained certificates/keys.
  3. Choose what you want as output, e.g. "Fullchain" — Tessera orders server cert → intermediates (→ root optional) itself and offers the result for download. All common formats as input AND output (user decision 09.10., locked): PEM/CRT/CER (Base64), DER, PKCS#7 (.p7b/.p7c), PKCS#12 (.pfx/.p12 with password), private keys (PKCS#1, PKCS#8, encrypted/ unencrypted, RSA + EC), CSR; outputs: Fullchain, chain only (intermediates), single certificate, certificate + key (PEM bundle), PFX with chosen password. Module version + module changelog + guides are part of the task.
## Implementation Decisions

Flow / structure

  • ONE upload tab (first tab) where the user drops/selects multiple files and/or ZIPs (and may paste PEM text). Everything uploaded forms a shared working set (list of files with remove buttons and what was recognised in each). The other tabs (Analysieren, Aufteilen, Zusammenführen/Fullchain, Konvertieren, Vorlagen) work on that shared set instead of having their own upload fields. Users' words: "in einem Reiter die ZIP bzw. die Einzelzertifikate hochladen und die einzelnen Reiter verarbeiten diese dann".

Root certificate in Fullchain

  • Selectable, default WITHOUT root ("Root-Zertifikat mitnehmen" checkbox).

Missing intermediate

  • Tessera reports the gap clearly ("Zwischenzertifikat fehlt") and offers a button "Fehlendes Zertifikat holen" which fetches it from the certificate's AIA caIssuers URL — ONLY on button press, never automatically. Fetch must be SSRF-safe (http/https only, public addresses only — reuse the project's existing isPublicHttpUrl/SSRF guard pattern, size and time limits, no redirects to private targets) and the result marked as "nachgeladen".

Templates for target systems

  • Yes: one-click templates, e.g. Nginx, Apache, Windows/IIS (PFX), Nginx Proxy Manager (and other common ones at Claude's discretion, e.g. HAProxy combined PEM, Java keystore only if feasible without native tools — otherwise skip). Free selection of content + format remains available.

Claude's Discretion

  • Where the working set lives (prefer browser memory only, never persisted server-side; private keys and passwords never stored or logged); ZIP limits (size, file count, nesting, zip-bomb ratio); key-to-certificate matching display; how CSRs are shown; file naming of downloads; whether the server or browser does the crypto (follow the existing module architecture); exact tab names.
## Specific Ideas
  • Chain building via Issuer/Subject + Authority/Subject Key Identifier; clear gap messages; verify the private key matches the certificate.
  • Existing module already analyses correctly (user: "Die Analyse funktioniert bereits richtig") — keep that behaviour, check existing conversion functions and close gaps.
  • Current module version 1.1.0 — check the module-changelog rule in docs/anleitung-entwicklung.md ("Höchstens ein Sprung je Modul zwischen zwei Tessera-Freigaben"; last release v1.10.1 on 2026-10-06) to decide bump vs. extending an unreleased entry.

<canonical_refs>

Canonical References

  • .planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md
  • docs/anleitung-entwicklung.md (module changelog rules)
  • docs/anleitung-anwender.md section "Zertifikat-Manager"

</canonical_refs>