Prefer a pca-issued cert over the self-signed one, when available - #22
Merged
Merged
Conversation
caddy_generate_cert now checks for the `pca` CLI (JaneliaSciComp/personal-certificate-authority) on PATH and, if present and initialized, issues a CA-signed certificate through it instead of generating a self-signed one. This avoids the browser trust-store warning and, more importantly, the self-signed-cert CORS/fetch failures Fileglancer's own docs warn about for anything talking to this service programmatically. Purely opportunistic: falls straight back to the existing self-signed generation when pca isn't installed or hasn't been initialized, so nothing changes for anyone who hasn't opted in. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
3 of 4 tasks
Points at personal-certificate-authority's Integration.md instead of leaving "if pca is on PATH" unexplained -- pca now also supports `pixi global install --git`/`--path` directly (see that doc), so this is a one-command setup rather than a manual wrapper script. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
4 of 5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
caddy_generate_certnow checks for thepcaCLI (JaneliaSciComp/personal-certificate-authority) onPATHand, if present and initialized (pca init), issues a CA-signed certificate through it instead of generating a self-signed one.pca-issued cert is signed by a CA actually installed in the local trust store, so there's no browser warning to click through, and it avoids the "self-signed certs break CORS/fetch" problem Fileglancer's own docs call out for anything that talks to this service programmatically rather than through a browser tab.opensslgeneration whenpcaisn't installed or hasn't been initialized yet, so this is a no-op for anyone who hasn't opted in — no new required dependency, no config flag needed.Why
This is a hands-on companion to documenting Caddy integration in the
personal-certificate-authorityproject — using a real consumer to validate the pattern before writing it up generically.Test plan
bash -n container/caddy-lib.sh— syntax check passes.caddy-lib.shand calledcaddy_generate_certwith a stubpcabinary onPATHsimulating success, failure, and absence — confirmed correctCERT_FILE/KEY_FILEin all three cases, and confirmed the self-signed fallback path is byte-for-byte unchanged whenpcaisn't present.pca, runpca init, thenpixi run marimo-httpsand confirm the printed cert path is under~/.local/share/personal-certificate-authority/certs/marimo-https/instead ofhttps-cert/marimo-https.crt.🤖 Generated with Claude Code