Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_certs_local_ca Discord

Swarmauri Certs Local CA

A local certificate authority implementing the ICertService interface for issuing and verifying X.509 certificates. Useful for development and testing environments where you need to bootstrap a private PKI quickly.

Features

  • Generate CSRs with optional subject alternative names and certificate extensions.
  • Create self-signed CA certificates with sensible defaults (1-year validity, CA basic constraints).
  • Sign CSRs to produce leaf certificates, returning PEM or DER output.
  • Perform basic certificate verification that ensures the certificate is currently valid and reports issuer/subject metadata.
  • Parse certificates to extract key metadata and extension object identifiers.

Note: verify_cert only evaluates validity windows; it does not build trust chains or check revocation lists.

Supported algorithms

LocalCaCertService.supports() reports the following capabilities:

  • Key algorithms: RSA-2048, RSA-3072, EC-P256, Ed25519
  • Signature algorithms: RSA-PSS-SHA256, ECDSA-P256-SHA256, Ed25519
  • Features: CSR creation, self-signed issuance, CSR signing, verification, and parsing

Installation

Install the package with your preferred Python packaging tool:

pip install swarmauri_certs_local_ca
poetry add swarmauri_certs_local_ca

If you use uv, install it first (for example with pip install uv) and then add the package:

uv pip install swarmauri_certs_local_ca

Usage

Below is a minimal end-to-end example that issues and verifies a leaf certificate signed by a local certificate authority. The helper function _key creates the KeyRef objects required by the service.

import asyncio
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.primitives.asymmetric import rsa

from swarmauri_certs_local_ca import LocalCaCertService
from swarmauri_core.crypto.types import ExportPolicy, KeyRef, KeyType, KeyUse


def _key(name: str) -> KeyRef:
    sk = rsa.generate_private_key(public_exponent=65537, key_size=2048)
    pem = sk.private_bytes(
        serialization.Encoding.PEM,
        serialization.PrivateFormat.PKCS8,
        serialization.NoEncryption(),
    )
    return KeyRef(
        kid=name,
        version=1,
        type=KeyType.RSA,
        uses=(KeyUse.SIGN,),
        export_policy=ExportPolicy.SECRET_WHEN_ALLOWED,
        material=pem,
    )


async def main() -> None:
    svc = LocalCaCertService()
    ca_key = _key("ca")
    leaf_key = _key("leaf")

    # Create a certificate signing request for the leaf key.
    csr = await svc.create_csr(leaf_key, {"CN": "leaf"})

    # Sign the CSR with the CA key to produce a leaf certificate.
    cert = await svc.sign_cert(csr, ca_key, issuer={"CN": "ca"})

    # Verify the newly issued certificate.
    result = await svc.verify_cert(cert)
    print(result["valid"], result["subject"], result["issuer"])


asyncio.run(main())

verify_cert returns a dictionary containing the validity flag plus the RFC 4514 representations of the subject and issuer. For CA bootstrapping you can call create_self_signed to generate a root certificate and use parse_cert to inspect serial numbers, validity windows, and extension object identifiers.

Entry Point

The service registers under the swarmauri.cert_services entry point as LocalCaCertService.

Want to help?

If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.

Metadata

Release files for swarmauri_certs_local_ca 0.11.0.dev2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_certs_local_ca 0.11.0.dev2
File Size Uploaded
swarmauri_certs_local_ca-0.11.0.dev2.tar.gz 9.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_certs_local_ca 0.11.0.dev2
File Interpreter ABI Platform
swarmauri_certs_local_ca-0.11.0.dev2-py3-none-any.whl Python 3 none any Details

Total release size: 20.1 kB

Release files / swarmauri_certs_local_ca-0.11.0.dev2.tar.gz

Download URL swarmauri_certs_local_ca-0.11.0.dev2.tar.gz
Size 9.5 kB
Tags Source
SHA-256 checksum
How to use checksums
a1f097206593bbb87e9cc3d2a847fbd82abb0965294ddf956a2c3676fec4f4ec
BLAKE2b-256 checksum
How to use checksums
ce6e3b049b8aeea15205632aef66820f630a7fed77ca4e2d5e4ca9a8b0de98b3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_certs_local_ca-0.11.0.dev2-py3-none-any.whl

Download URL swarmauri_certs_local_ca-0.11.0.dev2-py3-none-any.whl
Size 10.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a780c301e20fc4600881c0e012dd02dd9f5653a267a4544db4e6d86fbf33bea1
BLAKE2b-256 checksum
How to use checksums
83f05a9c21779f5fb1b7eda409c8fde5e013909f1a5b6a1506c968c0aa61c539
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page