Crypto Domain Manager
Automate all your cryptographic needs!
Goals
- Zero downtime
- Automatic certificate renewal
- Spam protection
- Updated DNS records
Configure once and always stay up to date.
Use cases
- Renew letsencrypt certicates
- Derive all kinds of data from the signature
- Ensure everything is secure
External Service APIs
- Domain Certificate: letsencrypt.org
- DNS Record Updates: inwx.de
Linux Services
- DKIM signatures:
- rspamd
- Reload systemd services:
- apache2
- postfix
- dovecot
- rspamd
- traefik in Docker
Managed DNS Records
- TLSA - for DNS based authentication of named entities DANE
- DKIM - domain keys for email signatures and spam detection
- CAA - specify the CA
- DMARC, SPF, ADSP - configure secure DNS
No downtime strategy
Updating keys, certifcates and other needs 3 steps to prevent gaps in availabillity:
- Prepare: Create certificates, keys etc. and publish corresponding records to DNS.
- Rollover: Apply new certificates and keys, because now negative cache TTL on DNS is reached.
- Cleanup: Delete all no more needed stuff from disk and DNS.
Needed Plugins and Dependencies
- dnsuptools: to interface with DNS API -- updating DNS entries
- dehydrated: to get new certificate (included with cryptdomainmgr)
- rspamd: to create (and use) DKIM keys
Installation
These libraries are needed for pycurl used by dnsuptools for automatic ip retrieving:
apt install -y libcurl4-openssl-dev libssl-dev
This comman is used by dehydrated to communicate with letsencrypt for certificate renewal:
apt install -y curl
For DKIM we need rspamd:
apt install -y lsb-release wget # optional
CODENAME=`lsb_release -c -s`
wget -O- https://rspamd.com/apt-stable/gpg.key | apt-key add -
echo "deb [arch=amd64] http://rspamd.com/apt-stable/ $CODENAME main" > /etc/apt/sources.list.d/rspamd.list
echo "deb-src [arch=amd64] http://rspamd.com/apt-stable/ $CODENAME main" >> /etc/apt/sources.list.d/rspamd.list
apt update
apt install -y rspamd
Now install the cryptdomainmgr. This pulls all need dependencies.
python2 -m pip install cryptdomainmgr
Feel free to try python3, but inwx client doesn't support it.
python3 -m pip install cryptdomainmgr
Documentation
We need help here!
For now please look at:
- German project description and tutorial: https://www.entroserv.de/offene-software/cryptdomainmgr
- Slides: https://github.com/TheTesla/cryptdomainmgr-talk
- Look at the configfiles examples
hints:
- Multiple Configfiles with priority allowed
- Specify content of config file content as argument
Next goals
- improve documentation
- docker support - partly done, ToDo: label handling needed, daemon mode without external shell stript needed
- website
- automated tests - partly done
- nsupdate for DNS updates
Long term goals:
- ARC key renewal
- WPIA integration
- DNSSEC key renewal
- TXT record (may collide with SPF and other TXT based records)
- multi server support for one domain: TLSA delete by timeout
- constrain minimum renewal/phase time interval
- validations - ensure signatures are used correctly
- run as service
- PowerDNS support
Contributions
If you like the project feel free to give me a star. Please let us know if you use this project.
All kind of contributions are welcome.
Metadata
Release files for cryptdomainmgr 0.2.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cryptdomainmgr-0.2.8.tar.gz | 73.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cryptdomainmgr-0.2.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 150.4 kB
Release files / cryptdomainmgr-0.2.8.tar.gz
| Download URL | cryptdomainmgr-0.2.8.tar.gz |
|---|---|
| Size | 73.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f0df23a2f6d7327fc00209918ef3acf215e0264be499a4a3847443ee5dec73c9
|
|
BLAKE2b-256 checksum How to use checksums |
a662ff42893a8b6dc5d354f94e0ca0fa95a42b8775b80bc2efe9de44b5a8d77e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|
Release files / cryptdomainmgr-0.2.8-py3-none-any.whl
| Download URL | cryptdomainmgr-0.2.8-py3-none-any.whl |
|---|---|
| Size | 77.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1f756dfbeb2bae9ede0350bf6cfd240cb90f21877034f8e0a4d9962215f63256
|
|
BLAKE2b-256 checksum How to use checksums |
cbe7d4ee55eff50de3d957358c083ccfb2608bb4b9a7aca773fa0d30bbf32ee7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|