Eigenverft.NetLib.Security.Certificates
1.0.0.5
dotnet add package Eigenverft.NetLib.Security.Certificates --version 1.0.0.5
NuGet\Install-Package Eigenverft.NetLib.Security.Certificates -Version 1.0.0.5
<PackageReference Include="Eigenverft.NetLib.Security.Certificates" Version="1.0.0.5" />
<PackageVersion Include="Eigenverft.NetLib.Security.Certificates" Version="1.0.0.5" />
<PackageReference Include="Eigenverft.NetLib.Security.Certificates" />
paket add Eigenverft.NetLib.Security.Certificates --version 1.0.0.5
#r "nuget: Eigenverft.NetLib.Security.Certificates, 1.0.0.5"
#:package Eigenverft.NetLib.Security.Certificates@1.0.0.5
#addin nuget:?package=Eigenverft.NetLib.Security.Certificates&version=1.0.0.5
#tool nuget:?package=Eigenverft.NetLib.Security.Certificates&version=1.0.0.5
Eigenverft.NetLib.Security.Certificates
Create self-signed X.509 certificates and load PFX files with an explicit, policy-controlled recovery behavior.
✨ At a glance
| Capability | What it does | Starting point |
|---|---|---|
| Self-signed certificates | Create certificates for TLS, code signing, or email protection with RSA or ECDSA profiles | SelfSignedCertificateFactory.Create(...) |
| Managed PFX files | Load a valid certificate or return a generated recovery certificate | ManagedCertificateFile.LoadOrCreate(...) |
| Recovery policy | Control whether recovery material is kept in memory or persisted | CertificateRecoveryMode |
📦 Installation
dotnet add package Eigenverft.NetLib.Security.Certificates
🚀 Quick start
Load a managed certificate and generate a replacement only when the PFX is missing or expired:
using System;
using System.IO;
using System.Security.Cryptography.X509Certificates;
using Eigenverft.NetLib.Security.Certificates;
string password = Environment.GetEnvironmentVariable("APP_PFX_PASSWORD")
?? throw new InvalidOperationException("APP_PFX_PASSWORD is required.");
ManagedCertificateResult managed = ManagedCertificateFile.LoadOrCreate(
new ManagedCertificateFileOptions
{
FilePath = Path.Combine(AppContext.BaseDirectory, "certs", "worker.pfx"),
Password = password,
RecoveryMode = CertificateRecoveryMode.ReplaceExpired,
Replacement = new SelfSignedCertificateOptions
{
Subject = new CertificateSubject { CommonName = "worker.example" },
Purpose = CertificatePurpose.TlsServer,
DnsNames = new[] { "worker.example" },
},
});
using X509Certificate2 certificate = managed.Certificate;
Console.WriteLine($"{managed.Action}; persisted: {managed.Persisted}");
ManagedCertificateResult.Certificate is caller-owned and must be disposed. Use SelfSignedCertificateFactory.Create(...) directly when the application does not need a managed-file lifecycle.
🔐 Certificate and recovery behavior
SelfSignedCertificateFactory supports TLS server/client, code-signing, and email-protection purposes. Profiles include RSA 2048/3072 with SHA-256 and ECDSA P-256/SHA-256 or P-384/SHA-384. TLS server certificates require at least one DNS or IP subject alternative name.
PreserveExisting is the default recovery mode: a generated certificate is returned in memory, and the configured PFX path is not created or replaced. ReplaceExpired creates a missing PFX and replaces only an existing, successfully imported expired PFX. ReplaceAnyUnusable can overwrite existing files that fail import, password, read, or access checks, so it must not be used casually with externally managed credentials. None disables recovery and requires an existing, currently valid PFX with a private key.
Self-signed certificates are not automatically trusted by clients. Protect the PFX path and password using the application's deployment controls; this library does not configure filesystem ACLs or establish a certificate trust chain.
🔗 Related packages
The WebLib Kestrel.Sni package consumes these certificate helpers for configuration-driven SNI certificates; this package does not depend on Kestrel or ASP.NET Core. Hosting.DirectoryLayout offers a conventional AppCerts path, but certificate loading accepts an explicit file path. Machine binding and Data Protection are separate value/key-ring mechanisms: neither is applied automatically to PFX files by this package.
🎯 Target frameworks
net8.0net10.0
🔗 Project links
📄 License
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- No dependencies.
-
net8.0
- No dependencies.
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Eigenverft.NetLib.Security.Certificates:
| Package | Downloads |
|---|---|
|
Eigenverft.WebLib.Kestrel.Sni
Configuration-driven Kestrel listeners with SNI certificate selection, TLS policy, and certificate recovery. |
GitHub repositories
This package is not used by any popular GitHub repositories.
Initial capability package extracted from Eigenverft.NetLib.Infrastructure.