76a30458fc
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
80 lines
4.0 KiB
Markdown
80 lines
4.0 KiB
Markdown
# Quick Task 261009-ikt: Cert Manager Umbau: mehrere Dateien, ZIP, Fullchain, alle Formate - Context
|
|
|
|
**Gathered:** 2026-10-09
|
|
**Status:** Ready for planning
|
|
|
|
<domain>
|
|
## Task Boundary
|
|
|
|
Rework module "Zertifikat-Manager" (slug cert-manager; api `apps/api/src/cert-manager/`, web
|
|
`apps/web/src/app/(portal)/modules/cert-manager/`). Source of the request:
|
|
`.planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md` (user test 09.10.):
|
|
1. Bug: merging accepts only ONE file — selecting a second overwrites the first.
|
|
2. Upload of a ZIP (as delivered by a certificate vendor) — Tessera unpacks and analyses contained
|
|
certificates/keys.
|
|
3. Choose what you want as output, e.g. "Fullchain" — Tessera orders server cert → intermediates
|
|
(→ root optional) itself and offers the result for download.
|
|
All common formats as input AND output (user decision 09.10., locked): PEM/CRT/CER (Base64), DER,
|
|
PKCS#7 (.p7b/.p7c), PKCS#12 (.pfx/.p12 with password), private keys (PKCS#1, PKCS#8, encrypted/
|
|
unencrypted, RSA + EC), CSR; outputs: Fullchain, chain only (intermediates), single certificate,
|
|
certificate + key (PEM bundle), PFX with chosen password. Module version + module changelog +
|
|
guides are part of the task.
|
|
|
|
</domain>
|
|
|
|
<decisions>
|
|
## Implementation Decisions
|
|
|
|
### Flow / structure
|
|
- ONE upload tab (first tab) where the user drops/selects multiple files and/or ZIPs (and may paste
|
|
PEM text). Everything uploaded forms a shared working set (list of files with remove buttons and
|
|
what was recognised in each). The other tabs (Analysieren, Aufteilen, Zusammenführen/Fullchain,
|
|
Konvertieren, Vorlagen) work on that shared set instead of having their own upload fields.
|
|
Users' words: "in einem Reiter die ZIP bzw. die Einzelzertifikate hochladen und die einzelnen
|
|
Reiter verarbeiten diese dann".
|
|
|
|
### Root certificate in Fullchain
|
|
- Selectable, default WITHOUT root ("Root-Zertifikat mitnehmen" checkbox).
|
|
|
|
### Missing intermediate
|
|
- Tessera reports the gap clearly ("Zwischenzertifikat fehlt") and offers a button
|
|
"Fehlendes Zertifikat holen" which fetches it from the certificate's AIA caIssuers URL — ONLY on
|
|
button press, never automatically. Fetch must be SSRF-safe (http/https only, public addresses only
|
|
— reuse the project's existing `isPublicHttpUrl`/SSRF guard pattern, size and time limits, no
|
|
redirects to private targets) and the result marked as "nachgeladen".
|
|
|
|
### Templates for target systems
|
|
- Yes: one-click templates, e.g. Nginx, Apache, Windows/IIS (PFX), Nginx Proxy Manager (and other
|
|
common ones at Claude's discretion, e.g. HAProxy combined PEM, Java keystore only if feasible
|
|
without native tools — otherwise skip). Free selection of content + format remains available.
|
|
|
|
### Claude's Discretion
|
|
- Where the working set lives (prefer browser memory only, never persisted server-side; private keys
|
|
and passwords never stored or logged); ZIP limits (size, file count, nesting, zip-bomb ratio);
|
|
key-to-certificate matching display; how CSRs are shown; file naming of downloads; whether the
|
|
server or browser does the crypto (follow the existing module architecture); exact tab names.
|
|
|
|
</decisions>
|
|
|
|
<specifics>
|
|
## Specific Ideas
|
|
|
|
- Chain building via Issuer/Subject + Authority/Subject Key Identifier; clear gap messages;
|
|
verify the private key matches the certificate.
|
|
- Existing module already analyses correctly (user: "Die Analyse funktioniert bereits richtig") —
|
|
keep that behaviour, check existing conversion functions and close gaps.
|
|
- Current module version 1.1.0 — check the module-changelog rule in docs/anleitung-entwicklung.md
|
|
("Höchstens ein Sprung je Modul zwischen zwei Tessera-Freigaben"; last release v1.10.1 on
|
|
2026-10-06) to decide bump vs. extending an unreleased entry.
|
|
|
|
</specifics>
|
|
|
|
<canonical_refs>
|
|
## Canonical References
|
|
|
|
- .planning/todos/pending/2026-10-09-cert-manager-mehrere-dateien-zip-fullchain.md
|
|
- docs/anleitung-entwicklung.md (module changelog rules)
|
|
- docs/anleitung-anwender.md section "Zertifikat-Manager"
|
|
|
|
</canonical_refs>
|