{"_id":"@benpley/wappler-pki-operations","_rev":"3-a25f0df002e441d82c48ce415d145e05","name":"@benpley/wappler-pki-operations","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@benpley/wappler-pki-operations","version":"1.0.0","keywords":["wappler-extension","server-connect","module","pki","certificate","x509","ca","pkcs12","ssl","tls","node"],"author":{"name":"Ben Pleysier"},"license":"MIT","_id":"@benpley/wappler-pki-operations@1.0.0","maintainers":[{"name":"benpley","email":"ben@pleysier.com.au"}],"dist":{"shasum":"9304a3df85c4386ebf00be17adabc05c8a4daaa2","tarball":"https://registry.npmjs.org/@benpley/wappler-pki-operations/-/wappler-pki-operations-1.0.0.tgz","fileCount":6,"integrity":"sha512-dhdANMCmkRRkHJ9HlmzSZh0ReeoKZE3EuS5CUtQjt4gNQjuv1Polmf8GAUhy0810DABaLdLWt4VeOc1vdf30+w==","signatures":[{"sig":"MEUCIHWVd+f8zhfnbzZpzJ2GMfeokRcZOMBRRt9fesADb4agAiEA5IYFIgJWruJnVn4DZqfcw1js0RBw6DwjCoJYfRvFZ2A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65787},"_npmUser":{"name":"benpley","email":"ben@pleysier.com.au"},"_npmVersion":"10.9.3","description":"PKI (Public Key Infrastructure) operations for Wappler Server Connect - Generate and manage X.509 certificates, Certificate Authorities, and PKCS#12 bundles","directories":{},"_nodeVersion":"22.19.0","dependencies":{"uuid":"^9.0.0","node-forge":"^1.3.1"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/wappler-pki-operations_1.0.0_1770160580822_0.3485361672895415","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-beta.2":{"name":"@benpley/wappler-pki-operations","version":"0.2.0-beta.2","keywords":["wappler-extension","server-connect","module","pki","certificate","x509","ca","pkcs12","ssl","tls","node"],"author":{"name":"Ben Pleysier"},"license":"MIT","_id":"@benpley/wappler-pki-operations@0.2.0-beta.2","maintainers":[{"name":"benpley","email":"ben@pleysier.com.au"}],"dist":{"shasum":"27f35b16b2382105d99567056d2fba51f69d1963","tarball":"https://registry.npmjs.org/@benpley/wappler-pki-operations/-/wappler-pki-operations-0.2.0-beta.2.tgz","fileCount":6,"integrity":"sha512-Lo0CN/e91n88LZYBu8fWHLChCr01UkgAHLs2c+nhNRFK/Mw7cepSp4zpYjN4UO8pff/SUpodgmxlfukq/6uxCg==","signatures":[{"sig":"MEYCIQCzhBze+udzDtVp4aWI7ekHEOfbzFeWeeIoxXWxK6u2VQIhAOfn5N5zztVytjxQ9moSFDKxNQ6MN/ACMYJmfClMn6v6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65841},"_npmUser":{"name":"benpley","email":"ben@pleysier.com.au"},"_npmVersion":"10.9.3","description":"PKI (Public Key Infrastructure) operations for Wappler Server Connect - Generate and manage X.509 certificates, Certificate Authorities, and PKCS#12 bundles","directories":{},"_nodeVersion":"22.19.0","dependencies":{"uuid":"^9.0.0","node-forge":"^1.3.1"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/wappler-pki-operations_0.2.0-beta.2_1770160876289_0.23126309590972038","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@benpley/wappler-pki-operations","version":"1.0.1","description":"PKI (Public Key Infrastructure) operations for Wappler Server Connect - Generate and manage X.509 certificates, Certificate Authorities, and PKCS#12 bundles","main":"server_connect/modules/pki.js","repository":{"type":"git","url":"git+https://github.com/your-org/your-repo.git"},"homepage":"https://github.com/your-org/your-repo#readme","bugs":{"url":"https://github.com/your-org/your-repo/issues"},"license":"MIT","author":{"name":"Ben Pleysier"},"keywords":["wappler-extension","server-connect","module","pki","certificate","x509","ca","pkcs12","ssl","tls","node"],"dependencies":{"node-forge":"^1.3.1","uuid":"^9.0.0"},"_id":"@benpley/wappler-pki-operations@1.0.1","_nodeVersion":"22.19.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-iewFrqkWIneSu+S0QmvuYZ4inPo9unpEjQlIs7hl1zVcxtam6z4HoqJJlXjkbLepidI5GaqzDjoE1+gFQpd8fA==","shasum":"70a03810695169ebd800dbfdab3d4d1fd67e0802","tarball":"https://registry.npmjs.org/@benpley/wappler-pki-operations/-/wappler-pki-operations-1.0.1.tgz","fileCount":6,"unpackedSize":69851,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCnBi+rFGwaeGjx1yEWyK2syYY/aSmLzZ5akcLkxVof5gIgUaVsZK2aJp2bn+9XSX7bJMOZf+Gfmf6rHG5to6X9VwU="}]},"_npmUser":{"name":"benpley","email":"ben@pleysier.com.au"},"directories":{},"maintainers":[{"name":"benpley","email":"ben@pleysier.com.au"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wappler-pki-operations_1.0.1_1770269744578_0.9428395828243537"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-03T23:16:20.687Z","modified":"2026-02-05T05:35:44.896Z","1.0.0":"2026-02-03T23:16:20.969Z","0.2.0-beta.2":"2026-02-03T23:21:16.448Z","1.0.1":"2026-02-05T05:35:44.731Z"},"author":{"name":"Ben Pleysier"},"license":"MIT","keywords":["wappler-extension","server-connect","module","pki","certificate","x509","ca","pkcs12","ssl","tls","node"],"description":"PKI (Public Key Infrastructure) operations for Wappler Server Connect - Generate and manage X.509 certificates, Certificate Authorities, and PKCS#12 bundles","maintainers":[{"name":"benpley","email":"ben@pleysier.com.au"}],"readme":"# PKI Operations Server Connect Module\n\nThis module provides comprehensive Public Key Infrastructure (PKI) operations for Wappler NodeJS projects. Generate X.509 certificates, create Certificate Authorities (CA), sign certificates, create PKCS#12 bundles, and verify certificate validity - all server-side within your Wappler workflows.\n\n## Features\n- **Generate Self-Signed Certificates**: Create X.509 end-entity certificates with RSA key pairs\n- **Create Certificate Authorities**: Generate CA certificates that can sign other certificates\n- **CA-Signed Certificates**: Sign end-entity certificates using your own CA\n- **PKCS#12 Bundles**: Create password-protected .p12/.pfx files for certificate distribution\n- **Certificate Verification**: Validate certificate authenticity, expiration, and signatures\n- **Flexible Security**: Support for password-protected private keys\n- **Multiple Key Sizes**: Choose from 2048, 3072, or 4096-bit RSA keys\n- **Configurable Validity**: Set certificate validity periods from 1 to 30 years\n\n## Available Actions\n\n![PKI Operations](https://unpkg.com/@benpley/wappler-pki-operations/images/pki-operations.png)\n\n### 1. Generate Certificate\nCreates a self-signed X.509 end-entity certificate with an RSA key pair.\n\n**Use Cases**: \n- Development and testing environments\n- Internal applications\n- Quick certificate generation without CA infrastructure\n\n**Output**:\n- `serialNumber`: Unique certificate serial number (UUID-based)\n- `certificatePEM`: Certificate in PEM format\n- `privateKeyPEM`: Unencrypted private key in PEM format (only returned when no password is provided; otherwise `null`)\n- `encryptedPrivateKeyPEM`: Password-encrypted private key in PEM format (if password provided, otherwise `null`)\n- `encrypted_private_key_pem`: Same as `encryptedPrivateKeyPEM` (snake_case for easier DB mapping; `null` when not encrypted)\n- `publicKeyPEM`: Public key in PEM format\n- `issuedDate`: Certificate issue date (ISO 8601)\n- `expiresDate`: Certificate expiration date (ISO 8601)\n- `fingerprint`: SHA-256 fingerprint\n\n**Configuration**:\n- **Common Name** *(required)*: Full name of certificate holder (e.g., \"John Doe\")\n- **Email Address** *(required)*: Valid email address\n- **Organization**: Organization name (default: \"InductEase PKI Certificate Authority\")\n- **Key Size**: 2048, 3072, or 4096 bits (default: 2048)\n- **Validity Period**: Years the certificate is valid (1-30, default: 1)\n- **Private Key Password**: Optional password to encrypt the private key\n\n### 2. Generate CA Certificate\nCreates a Certificate Authority certificate that can sign other certificates.\n\n**Use Cases**:\n- Building your own internal PKI infrastructure\n- Creating trusted certificate chains\n- Enterprise certificate management\n\n**Output**: Same as Generate Certificate\n\\*Note\\*: `privateKeyPEM` is only returned when no private key password is provided. When a password is supplied, `privateKeyPEM` will be `null` and the encrypted key outputs should be used.\n\n**Configuration**:\n- **CA Common Name** *(required)*: Name of your Certificate Authority (default: \"InductEase Root CA\")\n- **Organization** *(required)*: Organization name (default: \"InductEase PKI Certificate Authority\")\n- **Key Size**: 2048, 3072, or 4096 bits (default: 4096 for CA)\n- **Validity Period**: Years valid (typically 10-30, default: 10)\n- **CA Private Key Password** *(required)*: Strong password to protect CA private key (CRITICAL!)\n\n**Important**: The CA private key password is critical for security. Store it securely - losing it means you cannot sign certificates, and compromising it means anyone can sign certificates as your CA.\n\n### 3. Sign Certificate with CA\nSign an end-entity certificate using your Certificate Authority.\n\n**Use Cases**:\n- Issue trusted certificates to users/devices\n- Build certificate chains with your CA\n- Distribute CA-signed certificates instead of self-signed\n\n**Output**: Same as Generate Certificate\n\\*Note\\*: `privateKeyPEM` is only returned when no private key password is provided. When a password is supplied, `privateKeyPEM` will be `null` and the encrypted key outputs should be used.\n\n**Configuration**:\n- **Common Name** *(required)*: Certificate holder's full name\n- **Email Address** *(required)*: Certificate holder's email\n- **Organization**: Organization name\n- **CA Certificate (PEM)** *(required)*: Your CA certificate in PEM format\n- **CA Private Key (PEM)** *(required)*: Your CA private key (encrypted or unencrypted)\n- **CA Password**: Password for CA private key (if encrypted)\n- **Key Size**: 2048, 3072, or 4096 bits (default: 2048)\n- **Validity Period**: Years valid (1-30, default: 1)\n- **Private Key Password**: Optional password to encrypt the end-entity private key\n\n### 4. Generate PKCS#12\nCreate a password-protected PKCS#12 bundle (.p12/.pfx) containing certificate and private key.\n\n**Use Cases**:\n- Distribute certificates to end users\n- Import certificates into browsers, email clients, or devices\n- Bundle certificate with CA chain for complete trust\n\n**Output**:\n- `pkcs12Base64`: Base64-encoded PKCS#12 bundle\n- `friendlyName`: Friendly name stored inside the PKCS#12 bundle\n- `format`: Output format identifier\n- `hasCAChain`: Whether a CA chain was included in the bundle (boolean)\n\n**Configuration**:\n- **Certificate (PEM)** *(required)*: The certificate to bundle\n- **Private Key (PEM)** *(required)*: The private key to bundle\n- **CA Certificate (PEM)**: Optional CA certificate to include\n- **PKCS#12 Password** *(required)*: Password to protect the bundle\n- **Friendly Name**: Display name for the certificate in certificate stores\n\n**Optional overrides**:\n- **pkcs12Algorithm**: Algorithm to use (default: `3des`)\n- **pkcs12Iterations**: Iterations/work factor (default: `10000`)\n\n**Note**: The output `pkcs12Base64` can be decoded and saved as a .p12 or .pfx file for distribution.\n\n### 5. Verify Certificate\nVerify the validity and authenticity of an X.509 certificate.\n\n**Use Cases**:\n- Validate certificate before use\n- Check certificate expiration\n- Verify CA signature on certificates\n\n**Output**:\n- `isValid`: Overall validity status (boolean)\n- `isSignatureValid`: Whether the certificate signature is valid (boolean)\n- `isExpired`: Whether the certificate has expired (boolean)\n- `isNotYetValid`: Whether the certificate is not yet valid (boolean)\n- `isCA`: Whether the certificate is a CA certificate (boolean)\n- `serialNumber`: Certificate serial number\n- `subject`: Certificate subject (object)\n- `issuer`: Certificate issuer (object)\n- `notBefore`: Validity start date\n- `notAfter`: Validity end date\n- `fingerprint`: SHA-256 fingerprint\n- `isCAVerified`: Whether CA verification was performed successfully (boolean)\n- `verificationError`: Verification error message/details (when verification fails)\n\n**Configuration**:\n- **Certificate (PEM)** *(required)*: Certificate to verify\n- **CA Certificate (PEM)**: Optional CA certificate to verify signature against\n\n## Dependencies\nThe module requires the following npm packages:\n- `node-forge` (^1.3.1) - PKI operations and certificate generation\n- `uuid` (^9.0.0) - Unique serial number generation\n\nThese dependencies are automatically installed when you add the module to your project.\n\n## Usage Examples\n\n### Example 1: Create a Self-Signed Certificate\n```\n1. Add \"Generate Certificate\" step to your Server Connect workflow\n2. Configure:\n   - Common Name: {{$_POST.fullName}}\n   - Email: {{$_POST.email}}\n   - Key Size: 2048\n   - Validity: 1 year\n   - Password: {{$_POST.certPassword}}\n3. Use the output:\n   - Store certificatePEM and encryptedPrivateKeyPEM (or encrypted_private_key_pem) in database\n   - Return to user or generate PKCS#12 for download\n```\n\n### Example 2: Build a CA and Issue Certificates\n```\nStep 1: Generate CA Certificate (one-time setup)\n   - Common Name: \"My Company Root CA\"\n   - Organization: \"My Company, Inc.\"\n   - Key Size: 4096\n   - Validity: 10 years\n   - Password: (strong password - store securely!)\n   - Save CA certificate and private key securely\n\nStep 2: Sign User Certificates (repeated for each user)\n   - Use \"Sign Certificate with CA\" action\n   - Provide CA certificate and private key from Step 1\n   - Configure user details (name, email)\n   - Output: CA-signed certificate trusted by your infrastructure\n```\n\n### Example 3: Create Downloadable Certificate Bundle\n```\nStep 1: Generate or sign a certificate\nStep 2: Add \"Generate PKCS#12\" step\n   - Certificate PEM: {{step1.certificatePEM}}\n   - Private Key PEM: {{step1.privateKeyPEM}}\n   - CA Certificate: {{your_ca_cert}} (optional)\n   - Password: {{$_POST.bundlePassword}}\n   - Friendly Name: {{$_POST.fullName}}\nStep 3: Decode and serve for download\n   - Use core:setvalue to decode base64: {{step2.pkcs12Base64.base64decode()}}\n   - Set content-type: application/x-pkcs12\n   - Set filename: certificate.p12\n```\n\n### Example 4: Verify Certificate Before Use\n```\n1. Add \"Verify Certificate\" step\n2. Provide certificate PEM from user upload or database\n3. Optionally provide CA certificate to verify signature\n4. Check output:\n   - If isValid == true: Certificate is good to use\n   - If isExpired == true: Certificate has expired\n   - If isSignatureValid == false: Certificate not signed by provided CA\n```\n\n## Security Best Practices\n\n1. **CA Private Keys**: \n   - Always password-protect CA private keys with strong passwords\n   - Store CA certificates and keys in secure, encrypted storage\n   - Limit access to CA operations to authorized personnel only\n\n2. **Private Key Passwords**:\n   - Use strong passwords for all private keys\n   - Never store passwords in plain text\n   - Consider using environment variables or secure vaults\n   - Plaintext private keys are no longer returned when an encryption password is supplied\n\n3. **Certificate Validity**:\n   - Use shorter validity periods for end-entity certificates (1-2 years)\n   - Use longer validity for CA certificates (10+ years)\n   - Implement certificate renewal processes before expiration\n\n4. **Key Sizes**:\n   - Use 4096-bit keys for CA certificates\n   - Use at least 2048-bit keys for end-entity certificates\n   - Consider 3072 or 4096 bits for high-security applications\n\n5. **Distribution**:\n   - Always protect PKCS#12 bundles with strong passwords\n   - Use secure channels to distribute certificates and passwords\n   - Provide separate communication for passwords (out-of-band)\n\n## Typical Workflows\n\n### Setting Up Your PKI\n1. Generate a CA certificate (one-time, secure storage required)\n2. Sign end-entity certificates using the CA\n3. Distribute certificates as PKCS#12 bundles\n4. Verify certificates before use\n\n### Certificate Lifecycle\n1. **Issuance**: Sign certificate with CA\n2. **Distribution**: Create PKCS#12 bundle for user\n3. **Validation**: Verify certificate periodically\n4. **Renewal**: Generate new certificate before expiration\n5. **Revocation**: (Future feature - consider implementing CRL or OCSP)\n\n## Common Use Cases\n\n- **User Authentication**: Issue certificates for secure login\n- **Email Signing**: S/MIME certificates for email encryption/signing\n- **Code Signing**: Sign applications or scripts\n- **Device Authentication**: IoT device certificates\n- **VPN Access**: Client certificates for VPN authentication\n- **Internal APIs**: Mutual TLS authentication\n- **Document Signing**: Digital signatures on documents\n\n## Limitations\n\n- RSA keys only (no ECDSA support currently)\n- No built-in certificate revocation list (CRL) generation\n- No OCSP responder functionality\n- Self-signed or single-tier CA only (no intermediate CA support)\n\n## Issues and Support\n\nFor bug reports, feature requests, or assistance, please use the [Wappler Community Forum](https://community.wappler.io/).\n\n## Future Enhancements\n\nPotential future features:\n- ECDSA key support\n- Certificate Revocation Lists (CRL)\n- OCSP responder\n- Intermediate CA support\n- CSR (Certificate Signing Request) handling\n- Certificate chain validation\n\n## Changelog\n\n### 1.0.1\n- Fixed node-forge subject/issuer API compatibility (no setAttrs usage)\n- Encrypted key output now includes both `encryptedPrivateKeyPEM` and `encrypted_private_key_pem`\n- Plaintext `privateKeyPEM` is not returned when password is provided (security hardening)\n- Verify output stabilized (`isCAVerified` and `verificationError` always present)\n- PKCS#12 optional overrides: `pkcs12Algorithm`, `pkcs12Iterations`\n\n### 0.2.0-beta.4\n- Last beta prior to stable.\n\n---\n\n**Version 1.0.0** - Initial release. Feedback welcome!\n","readmeFilename":"README.md","homepage":"https://github.com/your-org/your-repo#readme","repository":{"type":"git","url":"git+https://github.com/your-org/your-repo.git"},"bugs":{"url":"https://github.com/your-org/your-repo/issues"}}