{"_id":"2cca","_rev":"3-41dc89a3b65d8a05e39a25cfd29c6c61","name":"2cca","description":"2-cent Certification Authority","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"2cca","version":"1.0.0","description":"2-cent Certification Authority","main":"2cca","scripts":{"test":"echo \"Error: no test specified\" && exit 1","preinstall":"cc -o 2cca 2cca.c -lcrypto"},"bin":{"2cca":"./2cca"},"repository":{"type":"git","url":"git+https://github.com/randunel/2cca.git"},"license":"MIT","bugs":{"url":"https://github.com/randunel/2cca/issues"},"homepage":"https://github.com/randunel/2cca","gitHead":"19d49da3b5bd8536d4775430aec222c1412d34d3","_id":"2cca@1.0.0","_shasum":"93c395bc887421b602022a395b40556c5dfc634f","_from":".","_npmVersion":"3.3.12","_nodeVersion":"5.5.0","_npmUser":{"name":"randunel","email":"dkrandu@yahoo.com"},"dist":{"shasum":"93c395bc887421b602022a395b40556c5dfc634f","tarball":"https://registry.npmjs.org/2cca/-/2cca-1.0.0.tgz","integrity":"sha512-tZZcfY+P6lNhtajAkE/WqHPb+oVkZgrIA6qMVY4D5JxDO4QBzscmZC3Hz58wiVlMpivTSQmWMnlddJzAUBUEsA==","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHwikE3QKyqwU6S7S05S5kc0MH173lpT+vG94bq8e/P8AiEAtADpO4b3sBsUejIWoHrEBhrTXhSIIzDqVFr+tL0WvQM="}]},"maintainers":[{"name":"randunel","email":"dkrandu@yahoo.com"}],"_npmOperationalInternal":{"host":"packages-9-west.internal.npmjs.com","tmp":"tmp/2cca-1.0.0.tgz_1454619308465_0.6886336493771523"}}},"readme":"# 2cca\n2-cent Certification Authority\n\nThis program is meant to replace the easy-rsa scripts found in default\ninstallations for OpenVPN.\n\nTwo independent versions are provided here:\n- Python version (2cca.py) based on pyopenssl\n- A single-file C version based on OpenSSL\n\nThe Python version is placed in the Public Domain. It was used as a\nproof-of-concept to demonstrate everything could be done directly with\nOpenSSL without involving the command-line tools. It is completely usable\nto generate root, server, and client certificates.\n\nThe C version is MIT-licensed. See LICENSE.\n\nCompilation\n-----------\n\nUse 'make'. You can also compile with:\n\n    cc -o 2cca 2cca.c -lcrypto\n\nTested on:\n- ArchLinux on Raspberry Pi -- openssl 1.0.2.e-1\n- Debian on x64 -- openssl 1.0.2.e-1\n\nOn OSX you cannot use the system openssl libraries but you can substitue\nthem by libressl, available from brew. I got it to compile with:\n\n    export LIBRE=/usr/local/opt/libressl\n    cc -I$(LIBRE)/include -L$(LIBRE)/lib -o 2cca 2cca.c -lcrypto\n\nBrew says I am using version 2.3.1 of libressl.\n\nWhat it does\n------------\n\n2cca can generate certificates and keys for various roles.\nSupported roles are:\n- Root CA: a self-signed Certification Authority\n- Sub CA: a Certification Authority, signed by another CA\n- OpenVPN server\n- OpenVPN client\n- Web server\n\nSpecify which kind of certificate you want to create and indicate which\nfields and properties are needed. A certificate file and key will be\ncreated in the local directory in PEM format.\n\nUsage\n-----\n\nCreating certificates follows the same syntax for all types of\ncertificates:\n\n    2cca TYPE [properties]\n\n    TYPE        Description\n    ----        -----------\n    root        Create a (self-signed) root CA certificate\n    sub         Create a Subordinate CA certificate\n    server      Create an OpenVPN server certificate\n    client      Create an OpenVPN client certificate\n    www         Create a Web server certificate\n\nCertificate fields and properties are specified on the command line by\nspecifying a list of key=value blocks. If the value contains blanks,\nsurround the whole block with double or simple quotes. Supported keys and\ntheir meaning are:\n\n    Key      Meaning                 Example                   Default\n    ---      -------                 -------                   -------\n    O        Organisation            \"O=ACME Inc\"              O=Home or root\n    C        Country 2-letter code   C=UK                      none\n    CN       Common Name             CN=MyServer               same as TYPE\n    L        Locality or City        L=Munich                  none\n    ST       State                   ST=Bavaria                none\n    email    Email                   email=root@example.com    none\n    ca       Signing CA              ca=Sub                    ca=root\n    days     Duration                days=15                   days=365\n    dns      Host name               dns=www.example.com       none\n\n    The O field (Organization) defaults to O=Home for root and is always\n    inherited from the issuer.\n\n    The OU field (Organizational Unit) is automatically set by certificate\n    type:\n\n    Type    OU\n    ----    --\n    root    OU=Root\n    sub     OU=Sub\n    server  OU=Server\n    client  OU=Client\n    www     OU=Server \n\n\n\nFile names\n----------\n\nCertificate and key are saved in the current directory as CN.crt and\nCN.key, where CN is the requested Common Name. For client identities, a\npassword-less P12 is also generated.\n\nThe default signing CA is named CN=root. If you change the root name\n(CN=xx) or want to use a specific CA for signature, use ca=NAME, where NAME\nis the CN for the CA you want to use. Example:\n\n    # Generate a root called MyROOT:\n    2cca root CN=MyROOT C=UK\n    -> Generates MyROOT.crt and MyROOT.key\n\n    # Generate a Sub CA called MySUB and sign it with MyROOT:\n    2cca sub ca=MyROOT CN=MySUB C=UK\n    -> Generates MySUB.crt and MySUB.key, signed by MyROOT\n\n    # Generate a client certificate for 'joe' and sign it with MySUB:\n    2cca client ca=MySUB CN=joe C=UK\n    -> Generates joe.crt, joe.key, joe.p12, signed by MySUB\n\n    # If you want to verify the chain with openssl:\n    cat MyROOT.crt MySUB.crt > bundle\n    openssl verify -CAfile bundle joe.crt\n    -> joe.crt: OK\n\nCertificate Duration\n--------------------\n\nChange certificate duration using days=xx where xx is in days from\ntoday. Default certificate duration is 3650 days. Example:\n\n    # Generate a client certificate for 15 days:\n    2cca client days=15 ca=MyROOT\n\nCrypto Parameters\n-----------------\n\nYou can generate RSA keys by specifying a key size with rsa=xx\nExample:\n\n    Generate a root certificate with a 4096 RSA key:\n    2cca root rsa=4096\n\nYou can also generate elliptic-curve keys for clients and servers. Use\nec=curve, where curve is one of the named curves supported by openssl. You\ncan get a list of elliptic curves supported on your system by running:\n\n    openssl ecparam -list_curves\n\nExamples:\n\n    # Generate a client cert with an ECC key with curve prime256v1\n    2cca client ec=prime256v1\n\nThe default hash function is sha256. There is currently no way to change\nthis from the command-line.\n\n\nCertificate Revocation Lists\n----------------------------\n\nPrimitive CRL management is also offered. The two associated commands are:\n\n    2cca revoke NAME ca=xx\n    2cca crl ca=xx\n\nYou revoke a certificate by name, i.e. by CN, which also happens to be the\nbase file name. To revoke joe's certificate issued by MySUB:\n\n    # Revoke joe issued by MySUB\n    2cca revoke joe ca=MySUB\n\nYou can review the CRL for a CA like this:\n\n    # See CRL for ca=MySUB\n    2cca crl ca=MySUB\n    -- Revoked certificates found in CRL\n    serial: 2CCA95D9A9F95BEE6C44564E0A514B45\n    date: Jan 19 22:04:51 2016 GMT\n\n    # Display the CRL using openssl\n    openssl crl -in MySUB.crl -text\n\n\nDiffie-Hellmann Parameters\n--------------------------\n\nYou can also generate Diffie-Hellmann parameters. Useful for OpenVPN\nsetups.\n\n    # Generate DH-2048 parameters\n    2cca dh\n    Generating DH parameters (2048 bits) -- this can take long\n    done\n\nIt takes ages to generate these, and the command does not display any\nprogress. You probably want to do it with OpenSSL. I just coded it for\nconvenience when the openssl command is not present.\n\n\nComplete Example\n----------------\n\nStarting from scratch, you want to first create a root (self-signed) CA.\nIt will be named 'MyRoot', for a duration of 1000 days, have a 1024-bit RSA\nkey, and be based in the UK.\n\n    2cca root CN=MyRoot days=1000 rsa=1024 C=UK\n\nCheck that you now have MyRoot.crt and MyRoot.key in the current directory.\n\nYou want two Sub-CAs then: one to handle OpenVPN servers and clients, and\nanother one to handle WWW server certificates. Both are children of the\nroot you just created.\n\n    # Generate the OpenVPN CA named 'VPNCA' for 900 days, 1024-bit RSA:\n    2cca sub CN=VPNCA days=900 rsa=1024 ca=MyRoot C=UK\n    # Generate the www server CA named 'WWWCA' for 500 days, 1024-bit RSA:\n    2cca sub CN=WWWCA days=500 rsa=1024 ca=MyRoot C=UK\n\nYou now have VPNCA.[crt|key] and WWWCA.[crt|key] in the current directory.\n\nLet us now issue client and server certificates for OpenVPN with the\nappropriate CA. We will use 512-bit RSA keys and set a validity period of\none year for the server, and two weeks for the client.\n\n    # Generate a cert for server named 'vpn-server' for 365 days, 512-bit RSA:\n    2cca server ca=VPNCA days=365 CN=vpn-server rsa=512 C=UK\n    # Generate a cert for a client named 'joe' for 15 days, 512-bit RSA:\n    2cca client ca=VPNCA days=15 CN=joe rsa=512 C=UK\n\nYou can now install vpn-server.[crt|key] in the appropriate places and send\nthe client credentials to Joe: either send joe.[crt|key] or joe.p12\n\nLet us issue a web server certificate for a server named 'www.example.com'\nfor a duration of one year, with a 2048-bit RSA key:\n\n    # Generate a web server certificate\n    2cca www ca=WWWCA days=365 rsa=2048 CN=www.example.com dns=www.example.com\n\nCheck that you have files called\nwww.example.com.[crt|key] in the current directory.\n\nYou can also issue certificates that arte valid for multiple domains or\njoker certificates by issuing several dns= properties on the command-line.\nExample:\n\n    # Generate a certificate for *.dom1.abc and *.dom2.abc\n    2cca www ca=WWWCA \"dns=*.dom1.abc\" \"dns=*.dom2.abc\"\n\nWarnings\n--------\n\nThere is no database of issued certificates to maintain because they use\n128-bit serial numbers, thus are already unique without having to remember\nan increasing index.\n\nThere is absolutely no key protection whatsoever. You are in charge of\nprotecting the .key files as you need. For personal VPNs this is not really\nan issue, but for something in need of security you probably want to import\nkeys into smart cards. This is meant to replace easy-rsa, not a\nfull-fledged PKI.\n\n-- nicolas314 - 2016-January\n\n","maintainers":[{"name":"randunel","email":"dkrandu@yahoo.com"}],"time":{"modified":"2022-06-12T14:06:46.949Z","created":"2016-02-04T20:55:11.285Z","1.0.0":"2016-02-04T20:55:11.285Z"},"homepage":"https://github.com/randunel/2cca","repository":{"type":"git","url":"git+https://github.com/randunel/2cca.git"},"bugs":{"url":"https://github.com/randunel/2cca/issues"},"license":"MIT","readmeFilename":"README.md"}