Can someone review and test a PowerShell certificate renewal script?

0
2
Asked By MellowPine47 On

I'm developing a free, open-source certificate authority for use on local networks. It can automatically renew web-server certificates. Since ACME's account-management requirements seem excessive for this environment, I created a simpler custom renewal method. The server-side implementation is complete, and working client scripts already exist in Python and PHP for Linux- and BSD-based systems, where certificates are stored as files.

I now want to add Windows support. I used AI to produce an initial PowerShell conversion, but I don't know PowerShell well enough to verify that it is correct. I'm looking for someone who can help with three parts of the project:

1. Review the PowerShell script for correctness and security issues.
2. Adapt the process to install or update certificates in the Windows certificate store rather than writing certificate files directly. I believe this store is integrated with the Windows system configuration, but I'm not familiar with the details.
3. Test the script on a Windows web server and confirm that certificate renewal works in practice.

I don't have a Windows Server environment or experience managing Windows web servers, so guidance from someone familiar with PowerShell and the Windows certificate store would be greatly appreciated.

3 Answers

Answered By QuietHarbor6 On

The quickest route may be to create a temporary Windows virtual machine and test there. You can install a web server, import a test certificate, run the renewal script, and verify the certificate bindings without needing production infrastructure. PowerShell's certificate provider and commands such as Import-Certificate can help with the store, although web-server bindings may require separate commands depending on the server.

MellowPine47 -

I could learn the environment and build a test VM, but I have no Windows Server or PowerShell experience. Someone who already works with these tools could probably review and test the script much faster, which is why I asked for help.

Answered By BrightKite_31 On

A cross-platform implementation might be easier if the certificate-request logic were written in a language such as Go, with small platform-specific helpers. However, the final installation step still has to be platform-specific: Unix-like systems generally use certificate and key files, while Windows commonly uses certificate stores and web-server bindings. That Windows integration cannot be made completely portable.

MellowPine47 -

The Windows certificate store is the main obstacle. Even if the request protocol is shared across platforms, importing and binding the certificate on Windows still needs Windows-specific code.

Answered By CedarFox_82 On

Be careful with this kind of software. A certificate authority is a high-trust component, so I would not deploy an unfamiliar implementation without reviewing the code, understanding the key-handling model, and testing it in an isolated environment first. Open source helps because users can inspect and host it themselves, but it does not automatically make the system trustworthy.

MellowPine47 -

That's exactly why the project is open source and intended to be self-hosted. Users can inspect the implementation and decide whether it fits their needs. In practice, many people also trust browser root stores without personally auditing every included certificate.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.