Skip to content

Prefer a pca-issued cert over the self-signed one, when available - #22

Merged
mkitti merged 2 commits into
mainfrom
add-pca-cert-support
Sep 10, 2026
Merged

mkitti merged 2 commits into
mainfrom
add-pca-cert-support

Conversation

@mkitti

@mkitti mkitti commented Sep 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • caddy_generate_cert now checks for the pca CLI (JaneliaSciComp/personal-certificate-authority) on PATH and, if present and initialized (pca init), issues a CA-signed certificate through it instead of generating a self-signed one.
  • A pca-issued cert is signed by a CA actually installed in the local trust store, so there's no browser warning to click through, and it avoids the "self-signed certs break CORS/fetch" problem Fileglancer's own docs call out for anything that talks to this service programmatically rather than through a browser tab.
  • Purely opportunistic: falls straight back to the existing self-signed openssl generation when pca isn't installed or hasn't been initialized yet, so this is a no-op for anyone who hasn't opted in — no new required dependency, no config flag needed.

Why

This is a hands-on companion to documenting Caddy integration in the personal-certificate-authority project — using a real consumer to validate the pattern before writing it up generically.

Test plan

  • bash -n container/caddy-lib.sh — syntax check passes.
  • Manually sourced caddy-lib.sh and called caddy_generate_cert with a stub pca binary on PATH simulating success, failure, and absence — confirmed correct CERT_FILE/KEY_FILE in all three cases, and confirmed the self-signed fallback path is byte-for-byte unchanged when pca isn't present.
  • End-to-end: install pca, run pca init, then pixi run marimo-https and confirm the printed cert path is under ~/.local/share/personal-certificate-authority/certs/marimo-https/ instead of https-cert/marimo-https.crt.

🤖 Generated with Claude Code

caddy_generate_cert now checks for the `pca` CLI
(JaneliaSciComp/personal-certificate-authority) on PATH and, if present
and initialized, issues a CA-signed certificate through it instead of
generating a self-signed one. This avoids the browser trust-store
warning and, more importantly, the self-signed-cert CORS/fetch failures
Fileglancer's own docs warn about for anything talking to this service
programmatically. Purely opportunistic: falls straight back to the
existing self-signed generation when pca isn't installed or hasn't been
initialized, so nothing changes for anyone who hasn't opted in.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Points at personal-certificate-authority's Integration.md instead of
leaving "if pca is on PATH" unexplained -- pca now also supports
`pixi global install --git`/`--path` directly (see that doc), so this
is a one-command setup rather than a manual wrapper script.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant