grapeape-ca

A small self-hosted certificate authority for internal HTTPS. Runs as an isolated Linux container with a 4096-bit RSA root CA whose private key never leaves the box. A systemd timer checks the root's expiry daily and re-signs it a couple of days before it would lapse, reusing the same key so already-trusted devices never need to re-trust anything — just pick up the refreshed cert.

A companion script issues short-lived leaf certificates for individual internal services with correct SANs and extended key usage. A small status page — served over HTTPS using its own issued certificate, dogfooding the whole system — offers the root for download in the formats each major platform expects, plus plain-language trust instructions for Android, iOS, Chrome, Firefox, and common CLI tools.

Built with

  • OpenSSL
  • systemd timers
  • nginx
  • Shell scripting
  • Debian Linux