swarmauri_certs_csronly
A community-provided certificate service that builds PKCS#10 Certificate Signing Requests (CSRs).
Features
CsrOnlyServicefocused exclusively on generating standards-compliant PKCS#10 CSRs (RFC 2986).- Supports RSA (2048/3072/4096), ECDSA (P-256), and Ed25519 private keys.
- Adds subject alternative names, challenge passwords, and basic constraints when needed.
- Designed to interoperate with other Swarmauri certificate services that handle issuance/verification.
Prerequisites
- Python 3.10 or newer.
- PEM-encoded private key material available locally or via a
KeyRefprovider. - Subject metadata (CN, O, OU, etc.) for the entity requesting a certificate.
- Optional: SAN entries, basic constraints, and challenge passwords when integrating with stricter PKI workflows.
Installation
# pip
pip install swarmauri_certs_csronly
# poetry
poetry add swarmauri_certs_csronly
# uv (pyproject-based projects)
uv add swarmauri_certs_csronly
Usage
Generate a CSR for example.com with SAN entries using an existing private key:
import asyncio
from pathlib import Path
from swarmauri_certs_csronly import CsrOnlyService
from swarmauri_core.crypto.types import KeyRef
async def main() -> None:
key_ref = KeyRef(material=Path("example-key.pem").read_bytes())
service = CsrOnlyService()
csr_pem = await service.create_csr(
key=key_ref,
subject={"CN": "example.com", "O": "Example Inc"},
san={"dns": ["example.com", "www.example.com"]},
)
Path("example.csr").write_bytes(csr_pem)
print("CSR written to example.csr")
if __name__ == "__main__":
asyncio.run(main())
Advanced CSR Options
Fine-tune extensions and output encoding for specialized PKI workflows:
import asyncio
from pathlib import Path
from swarmauri_certs_csronly import CsrOnlyService
from swarmauri_core.crypto.types import KeyRef
async def build_der_csr() -> None:
key_ref = KeyRef(material=Path("root-ca-key.pem").read_bytes())
service = CsrOnlyService()
csr_der = await service.create_csr(
key=key_ref,
subject={"CN": "Example Root CA"},
extensions={"basic_constraints": {"ca": True, "path_len": 0}},
challenge_password="p@ssw0rd",
output_der=True,
)
Path("root-ca.csr.der").write_bytes(csr_der)
print("DER CSR saved to root-ca.csr.der")
if __name__ == "__main__":
asyncio.run(build_der_csr())
Best Practices
- Generate new key pairs and CSRs ahead of certificate expiry to allow review and approval time.
- Store private keys securely—
KeyRefcan reference hardware or cloud KMS-backed material rather than local files. - Keep SAN lists minimal and auditable to avoid issuing overly permissive certificates.
- Pair this service with a signing backend (e.g., CFSSL, ACME, Azure Key Vault) to form a complete issuance pipeline.
Metadata
Release files for swarmauri_certs_csronly 0.8.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_certs_csronly-0.8.3.tar.gz | 8.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_certs_csronly-0.8.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.1 kB
Release files / swarmauri_certs_csronly-0.8.3.tar.gz
| Download URL | swarmauri_certs_csronly-0.8.3.tar.gz |
|---|---|
| Size | 8.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3865004e8411ef52a04ee473f1e9abadfbccccbeda4bd0d029dd21473b43739c
|
|
BLAKE2b-256 checksum How to use checksums |
41a0ff4669421b88fd149ceac134c5feaa992d44d6e8c64332bc275df1208f69
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_certs_csronly-0.8.3-py3-none-any.whl
| Download URL | swarmauri_certs_csronly-0.8.3-py3-none-any.whl |
|---|---|
| Size | 9.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
291eea92964b3ae1d98d388a2088d24a5ab01e7b4461ed9418f27c96972911e9
|
|
BLAKE2b-256 checksum How to use checksums |
70737bb11205ced780b4c7ba26b462ae45c4cd1b8040726908ed9c9d4f9e4869
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|