Files
tessera-ctl/.planning/quick/261009-ikt-cert-manager-umbau-mehrere-dateien-zip-f/261009-ikt-CONTEXT.md
T
schalli 76a30458fc docs(quick-261009-ikt): Cert-Manager-Umbau
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-09 17:12:10 +02:00

80 lines
4.0 KiB
Markdown

# Quick Task 261009-ikt: Cert Manager Umbau: mehrere Dateien, ZIP, Fullchain, alle Formate - Context
**Gathered:** 2026-10-09
**Status:** Ready for planning
<domain>
## Task Boundary
Rework module "Zertifikat-Manager" (slug cert-manager; api `apps/api/src/cert-manager/`, web
`apps/web/src/app/(portal)/modules/cert-manager/`). Source of the request:
`.planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md` (user test 09.10.):
1. Bug: merging accepts only ONE file — selecting a second overwrites the first.
2. Upload of a ZIP (as delivered by a certificate vendor) — Tessera unpacks and analyses contained
certificates/keys.
3. Choose what you want as output, e.g. "Fullchain" — Tessera orders server cert → intermediates
(→ root optional) itself and offers the result for download.
All common formats as input AND output (user decision 09.10., locked): PEM/CRT/CER (Base64), DER,
PKCS#7 (.p7b/.p7c), PKCS#12 (.pfx/.p12 with password), private keys (PKCS#1, PKCS#8, encrypted/
unencrypted, RSA + EC), CSR; outputs: Fullchain, chain only (intermediates), single certificate,
certificate + key (PEM bundle), PFX with chosen password. Module version + module changelog +
guides are part of the task.
</domain>
<decisions>
## Implementation Decisions
### Flow / structure
- ONE upload tab (first tab) where the user drops/selects multiple files and/or ZIPs (and may paste
PEM text). Everything uploaded forms a shared working set (list of files with remove buttons and
what was recognised in each). The other tabs (Analysieren, Aufteilen, Zusammenführen/Fullchain,
Konvertieren, Vorlagen) work on that shared set instead of having their own upload fields.
Users' words: "in einem Reiter die ZIP bzw. die Einzelzertifikate hochladen und die einzelnen
Reiter verarbeiten diese dann".
### Root certificate in Fullchain
- Selectable, default WITHOUT root ("Root-Zertifikat mitnehmen" checkbox).
### Missing intermediate
- Tessera reports the gap clearly ("Zwischenzertifikat fehlt") and offers a button
"Fehlendes Zertifikat holen" which fetches it from the certificate's AIA caIssuers URL — ONLY on
button press, never automatically. Fetch must be SSRF-safe (http/https only, public addresses only
— reuse the project's existing `isPublicHttpUrl`/SSRF guard pattern, size and time limits, no
redirects to private targets) and the result marked as "nachgeladen".
### Templates for target systems
- Yes: one-click templates, e.g. Nginx, Apache, Windows/IIS (PFX), Nginx Proxy Manager (and other
common ones at Claude's discretion, e.g. HAProxy combined PEM, Java keystore only if feasible
without native tools — otherwise skip). Free selection of content + format remains available.
### Claude's Discretion
- Where the working set lives (prefer browser memory only, never persisted server-side; private keys
and passwords never stored or logged); ZIP limits (size, file count, nesting, zip-bomb ratio);
key-to-certificate matching display; how CSRs are shown; file naming of downloads; whether the
server or browser does the crypto (follow the existing module architecture); exact tab names.
</decisions>
<specifics>
## Specific Ideas
- Chain building via Issuer/Subject + Authority/Subject Key Identifier; clear gap messages;
verify the private key matches the certificate.
- Existing module already analyses correctly (user: "Die Analyse funktioniert bereits richtig") —
keep that behaviour, check existing conversion functions and close gaps.
- Current module version 1.1.0 — check the module-changelog rule in docs/anleitung-entwicklung.md
("Höchstens ein Sprung je Modul zwischen zwei Tessera-Freigaben"; last release v1.10.1 on
2026-10-06) to decide bump vs. extending an unreleased entry.
</specifics>
<canonical_refs>
## Canonical References
- .planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md
- docs/anleitung-entwicklung.md (module changelog rules)
- docs/anleitung-anwender.md section "Zertifikat-Manager"
</canonical_refs>