Back to project gallery
  • CLI
  • PKI
  • OpenSSL
  • Automated Testing
  • Static Typing
  • CI
  • AI-assisted Development

CertAdmin

A Python CLI that turns infrequent, error-prone OpenSSL client-certificate administration into explicit, repeatable workflows for a home-lab PKI. It handles enrolment, temporary PKCS#12 exposure, revocation and CRL regeneration while keeping OpenSSL as the source of truth. It is also my first project in which GenAI evolved from an occasional source of technical advice into an increasingly agentic software-development assistant.

Illustrative reconstruction of a dark terminal showing CertAdmin commands for listing, enrolling, and revoking client certificates, surrounded by subtle certificate and security symbols.

CertAdmin is a Python command-line application for managing client certificates in my private OpenSSL-based PKI. I built it because certificate administration in a small home infrastructure is infrequent enough that remembering the complete procedure becomes more difficult than executing any individual command.

The goal was therefore not to replace OpenSSL, but to turn those occasionally used, multi-step procedures into explicit and repeatable workflows.

The problem

My home infrastructure uses client certificates for mTLS authentication across a small number of users and devices.

Issuing or revoking a certificate involves several related operations: generating keys and certificate requests, signing certificates, creating installation bundles, making those bundles temporarily available to a device, cleaning them up afterwards, and maintaining certificate-revocation state.

These operations do not happen often. That makes a manually documented procedure surprisingly error-prone: months may pass between two occasions on which I need to remember all of the steps.

CertAdmin captures that operational knowledge in software.

From PKI advice to agentic development

CertAdmin is the first substantial project in which I explored how to use generative AI while developing software.

It began much more simply. I initially used ChatGPT to help me work out the OpenSSL commands needed for certificate administration. I then captured part of that procedure in a small script so that I would not have to reconstruct the workflow the next time I needed it.

As that script grew into a proper command-line application, I increasingly used GenAI as a development assistant rather than only as a source of answers. This became particularly important while building out the test suite: I experimented with giving an AI agent larger, bounded pieces of work, reviewing what it produced, finding gaps or incorrect assumptions, and iterating on the implementation and tests.

Review was not simply a one-way process in which I directed the assistant from a position of greater expertise. When it introduced an approach or technique that was unfamiliar or unclear to me, I asked it to explain the reasoning behind the choice and its consequences before I accepted it. This let me delegate more repetitive implementation work without giving up my own understanding of the code, and turned parts of the review process into opportunities to learn new techniques.

The project therefore became both a useful infrastructure tool and an early practical exploration of agentic AI-assisted software engineering. It helped me develop a clearer sense of which work can be delegated effectively, what context an agent needs, how to review work without treating unfamiliar code as a black box, and how AI assistance can support learning as well as implementation.

Approach

CertAdmin deliberately remains a thin layer over an ordinary OpenSSL certificate authority.

OpenSSL remains the authoritative source for certificate issuance and revocation. CertAdmin maintains a small JSON registry for convenient administrative metadata, but the CA does not depend on that registry or on CertAdmin itself.

This was an intentional architectural choice. If CertAdmin disappeared, the underlying PKI would still be understandable and manageable using OpenSSL and its normal files.

The application also relies on existing operating-system security mechanisms rather than introducing its own authentication model. Read-only operations can run normally, while commands that modify certificate or filesystem state require elevated privileges.

What it does

CertAdmin provides commands to:

Revoking a certificate also removes an exposed installation bundle if one is still present.

Engineering and safety

Because CertAdmin operates on security-sensitive state, potentially destructive behaviour is kept explicit.

State-changing commands require sudo, while dry-run mode allows their intended operations to be inspected without making changes. Existing generated files are protected against accidental replacement unless force-overwrite is explicitly requested.

Application code and PKI state are required to live separately, preventing sensitive CA material from accidentally becoming part of the source tree.

Registry updates use an exclusive file lock for read-modify-write operations and write to a temporary file before replacing the registry, reducing the risk of conflicting writes or leaving a partially written registry.

The project is packaged as a Python 3.13 application with a console entry point and uses type annotations throughout. Its development workflow includes pytest, branch-aware coverage reporting, mypy and Ruff, with all checks enforced through GitHub Actions.

In the current project snapshot, the automated suite contains 48 passing tests and reports 82% coverage of production code.

Design philosophy

A constraint throughout the project has been to avoid solving problems that the operating system and OpenSSL already solve well.

There is deliberately no database, web interface, account system or background service. Those features would increase deployment complexity and attack surface without helping the small environment the application is intended to manage.

I wanted the complete system to remain small enough to understand, audit and troubleshoot directly.

That makes CertAdmin less ambitious as a PKI platform, but considerably more appropriate for the problem it actually solves.