4 ms·
Thanks so much for putting this together. It’s stupid simple but that’s all it needs to be. I did something similar in the past for a self-hosted workflow, but
by brirec 2y ago
Thanks so much for putting this together. It’s stupid simple but that’s all it needs to be.
I did something similar in the past for a self-hosted workflow, but this looks a lot more well put-together, and honestly I never thought about using a git repository for a PKI even though it’s really perfect for one.
Edit: what I did in particular was automating easy-rsa to manage a PKI.
I wonder if using easy-rsa via GitHub actions would make sense over the shell scripts here. I didn’t look at them yet, but easy-rsa basically is a handful of shell scripts to run a local PKI. I think it originates with the OpenVPN project, but it’s flexible enough to use it for anything
- brirec 2y agoMaybe if I feel motivated enough I’ll fork it and make one that uses easy-rsa, because when I look at this I don’t really see any provisions to do anything like revoking, for instance. Or really much of anything besides signing CSRs.
- stanleydrew 2y agoI could add revocation but then I'd need a place to persist the CRL. I could persist it back to the repo itself, but I didn't want to add more complexity at the start. It's probably worth considering though, so I've added an issue.