Showcase: sovereign HTTPS demo server + local CA
Some checks failed
ci / check (push) Has been cancelled
Some checks failed
ci / check (push) Has been cancelled
serve-demo.mjs serves dist/ (app shell, SPA fallback) and instance/origin/ (signed packages + latest.json) on one HTTPS port; generates /sync-config.json with the pinned signing-key fingerprint from the published package and offers /rootCA.pem for phone trust. gen-certs.sh creates a local ECDSA CA + server cert with SANs for localhost, hotspot 10.42.0.1, and current interface IPs. No tunnels, no third parties: everything runs on this laptop. npm run demo:certs / demo:serve.
This commit is contained in:
parent
5b69b87394
commit
0e7d85b862
4 changed files with 191 additions and 0 deletions
43
scripts/gen-certs.sh
Executable file
43
scripts/gen-certs.sh
Executable file
|
|
@ -0,0 +1,43 @@
|
|||
#!/usr/bin/env bash
|
||||
# Sovereign demo certs — private CA + server cert, generated locally.
|
||||
# Phones install rootCA.pem once; the browser then trusts the server.
|
||||
# Usage: scripts/gen-certs.sh [host-or-ip ...]
|
||||
# (extra SAN entries; localhost/127.0.0.1/10.42.0.1 always included)
|
||||
set -euo pipefail
|
||||
DIR="$(cd "$(dirname "$0")/.." && pwd)/instance/certs"
|
||||
mkdir -p "$DIR"
|
||||
|
||||
SANS=("localhost" "127.0.0.1" "10.42.0.1")
|
||||
# auto-include current non-loopback IPv4 addresses
|
||||
while read -r ip; do [[ -n "$ip" ]] && SANS+=("$ip"); done < <(
|
||||
ip -4 -o addr show scope global 2>/dev/null | awk '{print $4}' | cut -d/ -f1
|
||||
)
|
||||
for extra in "$@"; do SANS+=("$extra"); done
|
||||
|
||||
for s in "${SANS[@]}"; do
|
||||
if [[ "$s" =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||
SAN_STR+="IP:$s,"
|
||||
else
|
||||
SAN_STR+="DNS:$s,"
|
||||
fi
|
||||
done
|
||||
SAN_STR="DNS:localhost,${SAN_STR%,}"
|
||||
|
||||
if [[ ! -f "$DIR/rootCA-key.pem" ]]; then
|
||||
openssl req -x509 -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -nodes \
|
||||
-keyout "$DIR/rootCA-key.pem" -out "$DIR/rootCA.pem" -days 825 \
|
||||
-subj "/CN=Lumen Demo CA/O=Lumen" \
|
||||
-addext "basicConstraints=critical,CA:TRUE" \
|
||||
-addext "keyUsage=critical,keyCertSign,cRLSign"
|
||||
echo "created CA: $DIR/rootCA.pem (install this on phones)"
|
||||
fi
|
||||
|
||||
openssl req -newkey ec -pkeyopt ec_paramgen_curve:prime256v1 -nodes \
|
||||
-keyout "$DIR/server-key.pem" -out "$DIR/server.csr" \
|
||||
-subj "/CN=Lumen Demo Server/O=Lumen"
|
||||
openssl x509 -req -in "$DIR/server.csr" \
|
||||
-CA "$DIR/rootCA.pem" -CAkey "$DIR/rootCA-key.pem" -CAcreateserial \
|
||||
-out "$DIR/server.pem" -days 397 \
|
||||
-extfile <(printf "subjectAltName=%s\nextendedKeyUsage=serverAuth\n" "$SAN_STR")
|
||||
rm -f "$DIR/server.csr"
|
||||
echo "created server cert: $DIR/server.pem SAN: $SAN_STR"
|
||||
Loading…
Add table
Add a link
Reference in a new issue