I'm developing a free, open-source Certificate Authority for use on local networks. It can automatically renew web-server certificates. Since it is designed for internal environments, I created a simpler custom renewal method instead of using ACME and its account-management workflow. The server-side implementation is complete, and I already have working client scripts in Python and PHP for Linux and BSD systems, where certificates are stored as files. I also created a PowerShell version with help from AI, but I don't know PowerShell well enough to verify that it is correct. I'm looking for someone who can review the script, adapt it to install or update certificates in the Windows certificate store, and test it on a Windows web server. The goal is to confirm that the complete renewal process works reliably on Windows.
3 Answers
Certificate infrastructure is a high-trust area, so I’d be very cautious about deploying a script without understanding and reviewing every part of it. Making the project open source helps because people can inspect and host it themselves, but the certificate-generation, authentication, renewal, and private-key handling logic still need careful independent review before being trusted.
The quickest way to validate this is probably to create a small Windows Server virtual machine or lab environment. You could test the script against a local web server, verify that the certificate and private key land in the correct certificate-store locations, and then confirm that the web server actually uses the renewed certificate. Even limited hands-on testing would reveal issues that a code review might miss.
I could eventually build a test environment, but I have no practical Windows Server, IIS, or PowerShell experience. I’m hoping someone familiar with that stack can review and test it more efficiently.
A cross-platform implementation could use a common client written in a language such as Go, with small platform-specific helpers for certificate installation. However, the Windows certificate store is inherently platform-specific, so there will still need to be Windows-specific code. On Linux and BSD, the client can write certificate files; on Windows, it must import and manage certificates through the appropriate certificate-store or PowerShell APIs.
Exactly—the certificate store is the part that prevents this from being completely platform-neutral. The Windows version needs to handle importing and selecting certificates in the Windows store rather than simply writing files.

That concern is fair, and it’s exactly why I want the PowerShell code reviewed rather than blindly relying on an AI-generated conversion. Since the project is open source, users can inspect and run it on infrastructure they control.