Skip to main content

CBOM4CERT

The CBOM4CERT is a free, open source tool to generate a CBOM (Cryptography Bill of Materials) for one of more installed certificates in CycloneDX format.

Installation

To install use the following command:

pip install cbom4cert

Alternatively, just clone the repo and install dependencies using the following command:

pip install -U -r requirements.txt

The tool requires Python 3 (3.9+). It is recommended to use a virtual python environment especially if you are using different versions of python. virtualenv is a tool for setting up virtual python environments which allows you to have all the dependencies for the tool set up in a single environment, or have different environments set up for testing using different versions of Python.

Usage

usage: cbom4cert [-h] [-c CERTIFICATE] [--system] [--path PATH] [-d] [--sbom {spdx,cyclonedx}] [--format {tag,json,yaml}] [-o OUTPUT_FILE] [-V]

CBOM4cert generates a Cryptography Bill of Materials for one or more installed certificates.

options:
  -h, --help            show this help message and exit
  -V, --version         show program's version number and exit

Input:
  -c CERTIFICATE, --certificate CERTIFICATE
                        filename of certificate
  --system              include all installed python modules within system
  --path PATH           path to directory of certificates

Output:
  -d, --debug           add debug information
  --sbom {spdx,cyclonedx}
                        specify type of sbom to generate (default: cyclonedx)
  --format {tag,json,yaml}
                        specify format of software bill of materials (sbom) (default: json)
  -o OUTPUT_FILE, --output-file OUTPUT_FILE
                        output filename (default: output to stdout)

Operation

The --certificate option is used to identify a certificate file. The --system option is used to indicate that the CBOM is to include all installed certificates. Currently the --certificate option only works for Linux based platforms.

One of --certicate or --system must be specified. If multiple options are specified, the --certificate option is used.

The --path option is to specify the path to a directory containing certificates.

The --sbom option is used to specify the format of the generated SBOM (the default is CycloneDX). The --format option can be used to specify the formatting of the SBOM (the default is Tag Value format for a SPDX SBOM). JSON format is supported for both SPDX and CycloneDX SBOMs).

The --output-file option is used to control the destination of the output generated by the tool. The default is to report to the console but can be stored in a file (specified using --output-file option).

Licence

Licenced under the Apache 2.0 Licence.

Limitations

The SPDX support is incomplete.

The --certificate option only works for Linix based platforms.

Feedback and Contributions

Bugs and feature requests can be made via GitHub Issues.

Metadata

Release files for cbom4cert 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for cbom4cert 0.1.1
File Interpreter ABI Platform
cbom4cert-0.1.1-py3-none-any.whl Python 3 none any Details

Release files / cbom4cert-0.1.1-py3-none-any.whl

Download URL cbom4cert-0.1.1-py3-none-any.whl
Size 12.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d4be9910755682d805b97f8a6efdc60ed3b1ce16e84e436589b8606a05ffa735
BLAKE2b-256 checksum
How to use checksums
e6025e796c178bdb684d75a6067b47eff4cd475ae2dd20e4911ad8543d40b74c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.8

Release history Release notifications | RSS feed

This release

0.1.1 This release

1 release file

0.1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page