easy-rsa
ubios-cert
Our great sponsors
easy-rsa | ubios-cert | |
---|---|---|
26 | 6 | |
3,881 | 162 | |
1.2% | - | |
9.4 | 5.9 | |
6 days ago | 5 months ago | |
Shell | Shell | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
easy-rsa
-
Running one’s own root Certificate Authority in 2023
Easy-rsa to the rescue. Been using it for a while, works great and makes life easier :)
Link: https://github.com/OpenVPN/easy-rsa
Summary from that page:
easy-rsa is a CLI utility to build and manage a PKI CA. In laymen's terms, this means to create a root certificate authority, and request and sign certificates, including intermediate CAs and certificate revocation lists (CRL).
-
How to invalidate the usage of a OpenVpn client without revoke it in the CA Server?
No, OpenVPN relies on the CA trust model. Anyone signed by the CA has access, unless they have been revoked (CRL): https://github.com/OpenVPN/easy-rsa/blob/master/doc/EasyRSA-Renew-and-Revoke.md
-
Best OpenVPN web UI for a small business
Then make do with the CLI. There might be some tooling to help you, e.g. https://github.com/OpenVPN/easy-rsa
-
AMA/Brown Bag: OpenVPN / EasyRSA
Hey folks. I'm one of the authors for Mastering OpenVPN, the author of Troubleshooting OpenVPN, and the maintainer of EasyRSA. In light of Apollo and other 3rd party apps going dark on the 30th, I figured I'd "turn in my notice" on Reddit and do the normal sysadmin data dump/brown bag before I'm gone. I've really enjoyed this group and hope things get sorted in the long run.
-
PFSense Tutorial - Self signing of SSL/TLS Certificate (cause not all have the money to buy one) - https://youtu.be/aj5FUFMn9f0
Correct. That applies to OpenVPN. There's a tool that OpenRSA maintains that help with creating those certificates, EasyRSA: https://github.com/OpenVPN/easy-rsa
-
Invalid Security Certificate Warnings are ANNOYING
Regarding the keys, csr and certificates it's pretty easy to manage them with easy-rsa (https://github.com/OpenVPN/easy-rsa)
-
How to import server or client certificate on AWS Certificate Manager (ACM)
$ git clone https://github.com/OpenVPN/easy-rsa.git
-
How to manage lots of self-signed certificates
Depending on your use case, either https://github.com/FiloSottile/mkcert or https://github.com/OpenVPN/easy-rsa
-
Totally local web server on HTTPS.
If you can add CAs to the hosts that will access this server, you can be your own certificate authority. mkcert is good, as mentioned elsewhere, or you can go all out: https://github.com/OpenVPN/easy-rsa
- Private CA management
ubios-cert
-
Installing an SSL Cert on UDM using acme.sh and Google Domains
Firstly, I used the tool ubios-cert and the installation instructions they provide to do the majority of this process. For a good number of DNS API providers, these instructions alone are sufficient (e.g. GoDaddy, Cloudflare, etc.).
-
Valid and free TLS / SSL certificates for UniFi Consoles with firmware V2.x+
ubios-cert got a major rewrite to get rid of firmware V1.x requirements (like podman) and now runs on the bare metal firmware V2.x+ for UniFi consoles.
-
UniFi OS UDM - Renew Expired Self Signed Certificate
And I wouldn't recommend waiting for it. In the meantime, you could try out or contribute to https://github.com/alxwolf/ubios-cert.
-
Invalid Security Certificate Warnings are ANNOYING
Highly recommend using alxwolf’s script if you already have a domain name. This runs locally on the UDM and automatically renews the certificate with letsencrypt or others. Works very well and is compatible with UnifiOS v2+.
-
UDM Pro unifi OS2.4.xx certificate LetsEncrypt
You should check out one of the other projects linked in the Unifi-utilities repo, https://github.com/alxwolf/ubios-cert. I just used this one of my updated UDM Pro without a problem.
-
UDM Pro Let’s Encrypt
This is the one I was talking about. https://github.com/alxwolf/ubios-cert
What are some alternatives?
OpenSSL - TLS/SSL and crypto library
unifi-udm-backup - A Docker container which copies automatic backups from the Unifi Dream Machine to a FTP server
cfssl - CFSSL: Cloudflare's PKI and TLS toolkit
udm-le - Let's Encrypt support for Ubiquiti UniFi OS
FreeIPA - Mirror of FreeIPA, an integrated security information management solution
unifios-utilities - A collection of enhancements for UnifiOS based devices
LetsEncrypt-PRTG - Post request script to install an SSL certificate obtained with Certify the Web or win-acme in PRTG.
udm-iptv - Helper tool for configuring routed IPTV on the UniFi Dream Machine (Pro)
BounCA - BounCA is a web tool to generate self-signed SSL certificates and setup a key infrastructure
acme.sh - A pure Unix shell script implementing ACME client protocol
certify - Professional ACME Client for Windows. Certificate Management UI, powered by Let's Encrypt and compatible with all ACME v2 CAs. Download from certifytheweb.com
unifi-pfsense - A script that installs the UniFi Controller software on pfSense and other FreeBSD systems