Releases: BartelLuis/PKIMaster
Release list
PKIMaster 0.4.0-1
PKIMaster 0.4.0-1 adds automated certificate operations and a redesigned console with persistent Light, Dark and System appearance.
New features
- Certificate templates with server-enforced validity, DNS domain, IP network, wildcard and role policies. Issuance and renewal retain a snapshot of the selected policy.
- Certificate ownership, service, host, environment, tags and notes; expanded inventory search, status filters and CSV export.
- Automatic parent CRL synchronization with signature, freshness and rollback validation.
- Scheduled encrypted SFTP backups, locally generated recovery keys, retention and fresh-host restore. Optional independently retained SHA-256 verification is available during restoration.
- External audit archives with chain verification, delivery checkpoints and conflict detection.
- TLS deployment checks compare the certificate served by a configured endpoint with the expected certificate, verify hostname and chain, and follow certificate renewal.
- ACME enrollment with single-use external account binding, HTTP-01/DNS-01 challenges, template restrictions, certificate issuance, renewal, revocation and account-key rollover.
- Responsive navigation, improved forms and certificate views, accessible mobile navigation, and persistent Light/Dark/System themes.
Install or upgrade
For Debian 13 (trixie), use the signed bartel.sh / packages repository:
sudo apt update
sudo apt install pkimasterAlternatively, download pkimaster_0.4.0-1_all.deb below and install with sudo apt install ./pkimaster_0.4.0-1_all.deb. SHA256SUMS covers the package and build metadata. The package supports amd64 and arm64 through architecture-independent Python code and Debian dependencies.
Existing CA identities, certificates, encrypted keys, users, MFA and audit history are preserved. ACME and external automation start disabled; configure them in the console. The automation timer runs every five minutes alongside the existing publication and monitoring timers.
Validation
Tested migration from an actual 0.3.0 installation; browser checks in desktop/mobile Light and Dark modes; real TLS and SFTP transports; backup restoration; and interoperability with Certbot's ACME client library. GitHub Actions runs the Python matrix, security checks, distribution checks, and Debian 13 build/install/reinstall/removal smoke tests.
See the README, ACME guide and automation guide for configuration and recovery procedures.
0.3.0-1
Changes
- Encrypted complete-state backups with fresh-TOTP administrator confirmation and a validated fresh-host restore assistant. The HTTPS supervisor installs recovered state with workers stopped, preserves the CA identity, and invalidates existing browser sessions.
- Monitoring for certificate, CA-chain and parent-CRL expiry, publication failures, and actual public CRL reachability, signatures and freshness. Configurable email or HTTPS webhook delivery includes deduplication, escalation, recovery notices and retry handling. The Debian monitoring timer runs every five minutes.
- One-use MFA recovery codes and controlled authenticator replacement with a local QR code. Recovery still requires normal first-factor sign-in; completing replacement invalidates previous sessions and recovery codes.
- Certificate renewal with prefilled CN, SANs and profile, a new CSR or generated key, and linked predecessor/successor details. Renewal leaves the predecessor unchanged and prevents duplicate successors.
Installation and upgrade
Download pkimaster_0.3.0-1_all.deb below and install on Debian 13:
sudo apt update
sudo apt install ./pkimaster_0.3.0-1_all.debSHA256SUMS covers the .deb and build metadata. Existing CA material and settings are retained on upgrade. Generate recovery codes under Account security, configure Monitoring & alerts, and rehearse Backup & restore on a fresh host. Fence the original host before recovering its CA identity. External HSM/Azure keys require the provider's own recovery process; encrypted local-state archives are limited to 128 MiB.
See backup and recovery and monitoring.
Verification
Automated tests cover authentication and recovery boundaries, concurrent certificate renewal, backup integrity and interrupted recovery, public CRL validation and notification behavior. A real Debian HTTPS/Gunicorn test verifies automatic restore, preserved CA identity and restored sign-in. Desktop/mobile browser checks cover all new workflows. Release assets come from the Debian 13 build and installed-package smoke checks.
0.2.4-1
Permanently delete revoked CAs and reuse their display names.
- Administrators can select Delete CA in the revoked CA archive, review the affected records, and type the exact CA name to confirm.
- Deletion removes the CA, its issued end-entity and subordinate certificates, signing requests, CRLs, local software keys, archived provider credentials, and its local publication configuration.
- A new CA may reuse the deleted name and receives a fresh key and ID. Deleted public URLs return HTTP 404 and are never reassigned to the new CA.
- Audit history and a public-key fingerprint remain to record deletion and prevent reuse of a revoked signing key. Other CAs and their publication settings are preserved.
- Deletion is serialized with CRL generation and publication; related database changes either all commit or all roll back.
PKCS#11/SoftHSM and Azure provider objects, files already uploaded to a publication server, distributed certificates, and existing backups are not deleted automatically. Active or pending non-revoked CAs must be revoked before deletion.
Install or upgrade on Debian 13:
sudo apt update
sudo apt install ./pkimaster_0.2.4-1_all.debThe release includes the Debian package, build metadata, and SHA256SUMS. Runtime state is retained during package upgrades; deletion happens only when an administrator explicitly confirms it in the console.
Validation: full Python 3.11-3.14 Linux and Python 3.14 Windows test matrix, security checks, Debian 13 build/install/upgrade/removal checks, and browser deletion/name-reuse flows at desktop and mobile widths.
0.2.3-1
PKIMaster 0.2.3-1 fixes CA initialization after revocation.
- Initialize a fresh Root, Intermediate or Issuing CA on the same host once the previous CA is revoked. Only one non-revoked CA is allowed, including a CA awaiting activation.
- Retain revoked CAs, issued certificates, requests, audit history and public certificate/CRL downloads in the archive. Every replacement receives a fresh signing key.
- Preserve encrypted credentials for archived external signing keys, and prevent replacement publication from overwriting retired CA files.
After upgrading, return to Certificate inventory and initialize the new CA with a unique display name. A certificate common name can be reused. Configure separate CRL/AIA URLs and an SFTP directory before enabling publication for the replacement; keep retired artifact URLs available. Archived external CRLs require continued access to their signing provider; automatic SFTP publication follows the current CA.
Install or upgrade on Debian 13:
sudo apt update
sudo apt install ./pkimaster_0.2.3-1_all.debRuntime state in /var/lib/pkimaster is preserved during upgrades. Back up the entire state directory consistently before upgrading.
The assets contain the Debian package, build metadata, and SHA256SUMS.
Validation: 237 automated tests; Python 3.11–3.14 on Linux and Python 3.14 on Windows; Debian 13 package installation, HTTPS startup, upgrade, revoked-CA replacement, and retained data after removal/purge; security checks. Browser replacement flow checked at desktop and mobile widths.
0.2.2-1
New CA certificates and certificate signing requests no longer contain an automatically assigned Path Length (pathLenConstraint).
Changes
- Remove the hardcoded Root
2, Intermediate1, and Issuing0path-length values. New CA certificates and CSRs contain criticalBasicConstraintswithCA=TRUEand no path-length field. - Accept externally issued CA certificates and CSRs whose path-length field is absent. Signing a legacy CSR with a numeric path length also produces a new certificate without that field.
- Check limits present in existing parent certificates against the actual CA chain during activation and before signing another CA. Intermediate signers provide their complete parent chain for this check.
- Preserve the existing CA-role hierarchy, signature checks, key ownership checks, independent approval, and certificate validity checks.
Existing certificates
This update affects newly generated CSRs and newly issued certificates. An existing signed certificate cannot be edited to remove its path length; it must be reissued. Existing parent-certificate constraints continue to apply to their descendants.
Install or upgrade on Debian 13
Download pkimaster_0.2.2-1_all.deb, then run:
sudo apt update
sudo apt install ./pkimaster_0.2.2-1_all.debThe package preserves existing CA data and accounts. Back up the complete /var/lib/pkimaster state before upgrading as described in the README.
Verification
Built from commit b4af395e191c3d32335bb9bdffd80af788903ba9. Regression coverage includes absent path-length fields, bounded/unbounded external CAs, full certificate-chain activation, and rejected approval when an existing ancestor limit is exhausted. DER inspection confirms the optional path-length INTEGER is absent from new certificates and CSRs.
Build metadata and SHA256SUMS are attached alongside the .deb. Download all four files into one directory and verify them with sha256sum --check SHA256SUMS.
0.2.1-1
This update fixes authenticator enrollment with Bitwarden and corrects notification colors.
Fixes
- Show a scannable QR code during TOTP enrollment. It includes the required SHA-256 algorithm, six digits, and 30-second period.
- Provide a complete, copyable setup URI for manual configuration in Bitwarden. Entering only the secret key in Bitwarden defaults to SHA-1 and produces codes that PKIMaster rejects.
- Keep the QR code and setup details available after an invalid code, with guidance for correcting the authenticator settings.
- Display errors in red, warnings in amber, successful actions in green, and informational messages in blue, with corresponding labels and accessible announcements.
- Generate QR codes locally using Debian's
python3-segnopackage. No enrollment secret is sent to an external QR service.
Install or upgrade on Debian 13
Download pkimaster_0.2.1-1_all.deb from the assets, then run:
sudo apt update
sudo apt install ./pkimaster_0.2.1-1_all.debThe package preserves existing CA data and accounts. Back up the complete /var/lib/pkimaster state before upgrading as described in the README.
If your initial enrollment failed in Bitwarden, reopen the PKIMaster enrollment page after upgrading. Scan its QR code into your Bitwarden entry, or paste the complete setup URI into Authenticator key (TOTP), save, and submit the newly generated code. Already activated authenticators continue to work with their existing configuration. A lockout caused by repeated failed codes still expires after 15 minutes.
Verification
The release is built from commit a156aaabb2db24e765a961ed05b07adab86afcac. Validation includes RFC TOTP reference vectors, independent SHA-256 enrollment tests, replay and throttling regressions, and desktop/mobile browser checks that decode the QR code and complete enrollment.
Build metadata and SHA256SUMS are attached alongside the .deb. Download all four files into one directory and verify them with sha256sum --check SHA256SUMS.
0.2.0-1
PKIMaster 0.2.0-1 packages the browser-managed private PKI for Debian 13 (trixie).
Highlights
- One Root, Intermediate, or Issuing CA per server, with independent approval of subordinate CA requests.
- Local, LDAP, and OpenID Connect authentication with mandatory TOTP MFA and administrator, operator, and auditor roles.
- Encrypted software keys, PKCS#11/SoftHSM, and Azure Key Vault signing providers.
- Certificate issuance and revocation, public CRL/AIA endpoints, and automated SFTP publication with background CRL renewal and retry handling.
- Hardened HTTPS systemd service using Debian dependencies, with browser configuration and preserved state across package upgrades.
- Security fixes for parent CRL parsing and SFTP host-signature handling; public GET requests avoid unnecessary full audit-history scans.
Install on Debian 13
Download pkimaster_0.2.0-1_all.deb from the release assets, then run:
sudo apt update
sudo apt install ./pkimaster_0.2.0-1_all.debThe service initially listens on https://127.0.0.1:8443. For remote setup:
ssh -L 8443:127.0.0.1:8443 administrator@pki-serverOpen https://localhost:8443/setup, create the first administrator, and enroll MFA. The initial HTTPS certificate is self-signed; there are no default credentials.
Upgrade notes
Back up the complete state directory with the service and publication worker stopped. Retain the original database and encryption secrets: a database-only backup cannot recover encrypted keys.
Databases containing multiple local CAs are refused at startup and require a reviewed migration before upgrading. Moving a source installation into /var/lib/pkimaster is an explicit migration. See the README and migration guidance.
Release files and verification
The architecture-independent Debian package, build metadata (.buildinfo and .changes), and SHA256SUMS are attached. Download all four assets into the same directory to verify them:
sha256sum --check SHA256SUMSBuilt from commit dfd0195597f0f24b22dbba2c3d72fa4f92f6f5a8. The Debian build and installation smoke test, Python CI, and security checks passed for this commit.