grapeape-ca
A small self-hosted certificate authority for internal HTTPS. Runs as an isolated Linux container with a 4096-bit RSA root CA whose private key never leaves the box. A systemd timer checks the root's expiry daily and re-signs it a couple of days before it would lapse, reusing the same key so already-trusted devices never need to re-trust anything — just pick up the refreshed cert.
A companion script issues short-lived leaf certificates for individual internal services with correct SANs and extended key usage. A small status page — served over HTTPS using its own issued certificate, dogfooding the whole system — offers the root for download in the formats each major platform expects, plus plain-language trust instructions for Android, iOS, Chrome, Firefox, and common CLI tools.
Built with
- OpenSSL
- systemd timers
- nginx
- Shell scripting
- Debian Linux