6326064ad3
- CertManagerService.mergeCerts: parse all files via detectFormat/parsePemChain/toForgeBuffer, concatenate PEM chain or build PKCS12 via toPkcs12Asn1 - Open Question 1 resolved: toPkcs12Asn1(null, certs, password) works in node-forge 1.4.0 (null private key accepted — cert-only PFX without fallback needed) - PFX output requires non-empty password → BadRequestException if missing (T-09-02) - All forge calls in try/catch → BadRequestException; password never logged (T-09-02) - bytesToHex→Buffer.from(hex,'hex')→base64 for binary safety (Pitfall 1 avoidance) - convertCert gains pfx output target (reuses same null-key toPkcs12Asn1 pattern) - FORMAT_MIME extended with pfx: 'application/x-pkcs12' - NotImplementedException import removed (no longer used) - 27/27 API cert-manager tests green; tsc --noEmit exits 0