2020-11-22 11:28:28 +01:00
|
|
|
# Browser PKCS#10 CSR generation PoC
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
This repository contains a small proof of concept implementation of browser
|
|
|
|
based PKCS#10 certificate signing request and PKCS#12 key store generation
|
|
|
|
using [node-forge](https://github.com/digitalbazaar/forge).
|
2020-11-22 11:28:28 +01:00
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
The backend is implemented in [Go](https://golang.org/) and utilizes openssl
|
|
|
|
for the signing operations. The instructions below have been tested on Debian
|
|
|
|
11 (Bullseye). Debian 10 works when you use a manual installation of Go.
|
2020-11-30 00:55:34 +01:00
|
|
|
|
2020-11-22 11:28:28 +01:00
|
|
|
## Running
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
1. Install dependencies
|
|
|
|
|
|
|
|
```
|
|
|
|
sudo apt install git npm openssl golang-go
|
|
|
|
```
|
|
|
|
|
|
|
|
2. Clone the repository
|
2020-11-22 11:28:28 +01:00
|
|
|
|
|
|
|
```
|
|
|
|
git clone https://git.dittberner.info/jan/browser_csr_generation.git
|
|
|
|
```
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
3. Get dependencies and build assets
|
2020-11-22 11:28:28 +01:00
|
|
|
|
|
|
|
```
|
|
|
|
cd browser_csr_generation
|
2022-04-24 19:19:51 +02:00
|
|
|
npm install --user gulp-cli
|
2020-11-22 11:28:28 +01:00
|
|
|
npm install
|
2022-04-24 19:19:51 +02:00
|
|
|
./node_modules/.bin/gulp
|
2020-11-22 11:28:28 +01:00
|
|
|
```
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
3. Setup the example CA and a server certificate and key
|
2020-11-30 00:55:34 +01:00
|
|
|
|
|
|
|
```
|
|
|
|
./setup_example_ca.sh
|
2022-04-24 19:19:51 +02:00
|
|
|
openssl req -new -x509 -days 365 -subj "/CN=localhost" \
|
|
|
|
-addext subjectAltName=DNS:localhost -newkey rsa:3072 \
|
2020-11-30 00:55:34 +01:00
|
|
|
-nodes -out server.crt.pem -keyout server.key.pem
|
|
|
|
```
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
4. Run the Go based backend
|
2020-11-22 11:28:28 +01:00
|
|
|
|
|
|
|
```
|
2020-11-30 00:55:34 +01:00
|
|
|
go run main.go
|
2020-11-22 11:28:28 +01:00
|
|
|
```
|
|
|
|
|
2020-12-05 00:21:18 +01:00
|
|
|
Open https://localhost:8000/ in your browser.
|
2020-11-22 11:28:28 +01:00
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
5. Run gulp watch
|
2020-11-22 11:28:28 +01:00
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
You can run a
|
|
|
|
[gulp watch](https://gulpjs.com/docs/en/getting-started/watching-files/)
|
|
|
|
in a second terminal window to automatically publish changes to the files in
|
|
|
|
the `src` directory:
|
2020-11-22 11:28:28 +01:00
|
|
|
|
|
|
|
```
|
|
|
|
gulp watch
|
|
|
|
```
|
2020-12-05 00:21:18 +01:00
|
|
|
|
|
|
|
## Translations
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
This PoC uses [go-i18n](https://github.com/nicksnyder/go-i18n/) for
|
|
|
|
internationalization (i18n) support.
|
2020-12-05 00:21:18 +01:00
|
|
|
|
|
|
|
The translation workflow needs the `go18n` binary which can be installed via
|
|
|
|
|
|
|
|
```
|
|
|
|
go get -u github.com/nicksnyder/go-i18n/v2/goi18n
|
|
|
|
```
|
|
|
|
|
|
|
|
To extract new messages from the code run
|
|
|
|
|
|
|
|
```
|
|
|
|
goi18n extract
|
|
|
|
```
|
|
|
|
|
|
|
|
Then use
|
|
|
|
|
|
|
|
```
|
|
|
|
goi18n merge active.*.toml
|
|
|
|
```
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
to create TOML files for translation as `translate.<locale>.toml`. After
|
|
|
|
translating the messages run
|
2020-12-05 00:21:18 +01:00
|
|
|
|
|
|
|
```
|
|
|
|
goi18n merge active.*.toml translate.*.toml
|
|
|
|
```
|
|
|
|
|
2022-04-24 19:19:51 +02:00
|
|
|
to merge the messages back into the active translation files. To add a new
|
|
|
|
language you need to add the language code to `main.go`'s i18n bundle loading
|
|
|
|
code
|
2020-12-05 00:21:18 +01:00
|
|
|
|
|
|
|
```
|
|
|
|
for _, lang := range []string{"en-US", "de-DE"} {
|
|
|
|
if _, err := bundle.LoadMessageFile(fmt.Sprintf("active.%s.toml", lang)); err != nil {
|
|
|
|
log.Panic(err)
|
|
|
|
}
|
|
|
|
}
|
2022-04-24 19:19:51 +02:00
|
|
|
```
|