Sign inSign up

cplieger/cert-converter

By cplieger

•Updated about 19 hours ago

Keep PFX copies current as your PEM certificates renew, and turn PFX bundles back into PEM

Image
Security
0

10K+

cplieger/cert-converter repository overview

⁠cert-converter

cert-converter keeps PFX copies of your certificates current as they renew, for apps that accept only PFX. It does not request certificates or restart the apps that read them.

⁠What it does

cert-converter renews the PFX file your app reads each time its certificate renews.

  • Writes a password-protected PFX file for each <name>.crt and <name>.key pair, with the chain from the .crt file.
  • Converts again a few seconds after a renewal, and rechecks the whole folder every 6 hours by default.
  • Can also turn PFX or P12 bundles into PEM files, or write PEM copies beside the PFX files.
  • Leaves a file untouched while it matches its certificate, password and encoding profile.

⁠Who it is for

cert-converter is built for people whose reverse proxy or certificate tool already renews certificates as files, and who run an app that takes only PFX. Examples are .NET apps, Windows tools and the Synology services that take only PFX. It reads <name>.crt and <name>.key pairs, the way Caddy saves each site's certificate. Certbot's fullchain.pem and privkey.pem are not read. Your app must reread the PFX file, or be restarted, to use a renewed certificate.

You need Docker on an amd64 or arm64 machine, and read access to the certificate files for the container's user.

Consider acme.sh⁠ if you want your certificate tool to write the PFX file itself. Its --to-pkcs12 command exports a certificate and key as a password-protected PFX file.

cert-converter is free software under the GPL-3.0-or-later license.

⁠Pull

docker pull cplieger/cert-converter:latest

Also published to ghcr.io/cplieger/cert-converter with identical images and tags. Release versions are tagged vX.Y.Z alongside latest.

⁠Quick start

# Example compose for cert-converter. See the README for all configuration options and hardening.
services:
  cert-converter:
    image: ghcr.io/cplieger/cert-converter:latest
    container_name: cert-converter
    restart: unless-stopped
    # In .env, set PUID and PGID to the user and group that own the certificate files.
    # Create the output folder and run "sudo chown 1000:1000" on it, with those numbers, before the first start.
    user: "${PUID:-1000}:${PGID:-1000}"

    environment:
      # Put PFX_PASSWORD=<a password> in .env. The container does not start without one.
      # docker inspect shows this value. See README "Security" to use a secret file instead.
      PFX_PASSWORD: "${PFX_PASSWORD:-}"
      # warn keeps converted files whose certificate is gone, sync deletes them, keep stays silent.
      # Use sync only once /input holds every certificate you want converted.
      OUTPUT_LIFECYCLE: "${OUTPUT_LIFECYCLE:-warn}"
      PFX_ENCODER: "modern2023"  # modern2023, modern2026, legacy, or legacyrc2

    volumes:
      # The user above must be able to read this folder. See README "Quick start".
      - "/path/to/certificates:/input:ro"
      - "/path/to/converted/output:/output"

⁠Documentation

⁠License

GPL-3.0-or-later. See LICENSE⁠. The image carries the license text of every bundled component under /usr/share/licenses/.

Tag summary

Content type

Image

Digest

sha256:0fd4902b2…

Size

3.3 MB

Last updated

about 19 hours ago

docker pull cplieger/cert-converter