This release is a pre-release and may not be stable for production use.
Swarmauri Certs Local CA
A local certificate authority implementing the ICertService interface for issuing and verifying X.509 certificates. Useful for development and testing environments where you need to bootstrap a private PKI quickly.
Features
- Generate CSRs with optional subject alternative names and certificate extensions.
- Create self-signed CA certificates with sensible defaults (1-year validity, CA basic constraints).
- Sign CSRs to produce leaf certificates, returning PEM or DER output.
- Perform basic certificate verification that ensures the certificate is currently valid and reports issuer/subject metadata.
- Parse certificates to extract key metadata and extension object identifiers.
Note:
verify_certonly evaluates validity windows; it does not build trust chains or check revocation lists.
Supported algorithms
LocalCaCertService.supports() reports the following capabilities:
- Key algorithms:
RSA-2048,RSA-3072,EC-P256,Ed25519 - Signature algorithms:
RSA-PSS-SHA256,ECDSA-P256-SHA256,Ed25519 - Features: CSR creation, self-signed issuance, CSR signing, verification, and parsing
Installation
Install the package with your preferred Python packaging tool:
pip install swarmauri_certs_local_ca
poetry add swarmauri_certs_local_ca
If you use uv, install it first (for example with pip install uv) and then add the package:
uv pip install swarmauri_certs_local_ca
Usage
Below is a minimal end-to-end example that issues and verifies a leaf
certificate signed by a local certificate authority. The helper function
_key creates the KeyRef objects required by the service.
import asyncio
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.primitives.asymmetric import rsa
from swarmauri_certs_local_ca import LocalCaCertService
from swarmauri_core.crypto.types import ExportPolicy, KeyRef, KeyType, KeyUse
def _key(name: str) -> KeyRef:
sk = rsa.generate_private_key(public_exponent=65537, key_size=2048)
pem = sk.private_bytes(
serialization.Encoding.PEM,
serialization.PrivateFormat.PKCS8,
serialization.NoEncryption(),
)
return KeyRef(
kid=name,
version=1,
type=KeyType.RSA,
uses=(KeyUse.SIGN,),
export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
material=pem,
)
async def main() -> None:
svc = LocalCaCertService()
ca_key = _key("ca")
leaf_key = _key("leaf")
# Create a certificate signing request for the leaf key.
csr = await svc.create_csr(leaf_key, {"CN": "leaf"})
# Sign the CSR with the CA key to produce a leaf certificate.
cert = await svc.sign_cert(csr, ca_key, issuer={"CN": "ca"})
# Verify the newly issued certificate.
result = await svc.verify_cert(cert)
print(result["valid"], result["subject"], result["issuer"])
asyncio.run(main())
verify_cert returns a dictionary containing the validity flag plus the RFC 4514
representations of the subject and issuer. For CA bootstrapping you can call
create_self_signed to generate a root certificate and use parse_cert to
inspect serial numbers, validity windows, and extension object identifiers.
Entry Point
The service registers under the swarmauri.cert_services entry point as LocalCaCertService.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_certs_local_ca 0.11.0.dev2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_certs_local_ca-0.11.0.dev2.tar.gz | 9.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_certs_local_ca-0.11.0.dev2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.1 kB
Release files / swarmauri_certs_local_ca-0.11.0.dev2.tar.gz
| Download URL | swarmauri_certs_local_ca-0.11.0.dev2.tar.gz |
|---|---|
| Size | 9.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a1f097206593bbb87e9cc3d2a847fbd82abb0965294ddf956a2c3676fec4f4ec
|
|
BLAKE2b-256 checksum How to use checksums |
ce6e3b049b8aeea15205632aef66820f630a7fed77ca4e2d5e4ca9a8b0de98b3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_certs_local_ca-0.11.0.dev2-py3-none-any.whl
| Download URL | swarmauri_certs_local_ca-0.11.0.dev2-py3-none-any.whl |
|---|---|
| Size | 10.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a780c301e20fc4600881c0e012dd02dd9f5653a267a4544db4e6d86fbf33bea1
|
|
BLAKE2b-256 checksum How to use checksums |
83f05a9c21779f5fb1b7eda409c8fde5e013909f1a5b6a1506c968c0aa61c539
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|