Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Backup and export mechanism for Root CA and generated certificates (PKI backup support)

Aperta
#6,978 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Da chiarire
Stato di attività
Ferma
Stack tecnologico
php
Ambito
backend, security

Direzione di ricerca

Inizia esaminando come LibreSign archivia la Root CA, i certificati generati, i dati CRL e la configurazione di OpenSSL nella directory appdata di Nextcloud. Esamina quindi l’interfaccia di amministrazione e i punti di ingresso proposti occ libresign:backup e occ libresign:restore. Il lavoro sarà considerato completato quando sarà definito un percorso sicuro e documentato di backup e ripristino che preservi l’intera catena di attendibilità PKI.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

feature-request
Is your feature request related to a problem? Please describe.

LibreSign currently stores the Root CA and all generated certificates inside the Nextcloud appdata directory.

In production environments, these certificates represent legally binding digital signatures and form the trust chain of signed documents.

However:

  • There is no built-in way to export or back up the Root CA.
  • There is no official mechanism to back up the PKI structure.
  • Accidental deletion, corruption, migration, or update issues could permanently break the trust chain.
  • Regenerating a Root CA after loss would invalidate the long-term consistency of signatures and CRLs.
  • This creates a significant operational and legal risk in production environments.
Describe the solution you'd like

I would like LibreSign to provide an official and secure backup/export mechanism for:

  1. Root CA private key and certificate
  2. Full PKI directory (index, serial, CRL, etc.)
  3. Generated user certificates
  4. CRL data
  5. OpenSSL configuration used for the CA

Ideally, this could include:

  • A downloadable encrypted backup archive from the admin interface
  • A CLI command (e.g. occ libresign:backup)
  • Optional encryption with a passphrase
  • A restore command (e.g. occ libresign:restore)
  • Clear documentation on backup strategy for production

This would allow administrators to:

  • Implement disaster recovery plans
  • Securely store PKI off-server
  • Maintain long-term signature validity
  • Avoid catastrophic trust chain loss
Describe alternatives you've considered

Currently, the only workaround is to manually:

  • Identify the PKI directory inside appdata
  • Manually back up the entire directory via filesystem
  • Manually restore it if needed

This approach is:

  • Not officially documented
  • Error-prone
  • Risky for non-expert administrators
  • Potentially incompatible with future structural changes

Additionally, relying solely on filesystem backups does not provide a clear or supported recovery path.

Additional context

In production use cases where LibreSign is used for contractual signatures:

  • The Root CA must be preserved long-term
  • The CRL must remain consistent
  • Trust continuity must be guaranteed

An official backup/restore mechanism would significantly increase confidence in LibreSign for enterprise and compliance-sensitive environments.

This feature would help position LibreSign as a production-grade digital signature solution suitable for legal and contractual workflows.

If useful, I would be happy to help test or provide feedback on a backup/export implementation.

Lingua principale
PHP
Stelle
818
Fork
146
Merge medio
7h 38m
PR unite (30g)
490

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di LibreSign/libresign

Tutte le issue di LibreSign/libresign

Issue simili

Altre issue su PHP

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.