Eigenverft.NetLib.Security.Certificates 1.0.0.5

dotnet add package Eigenverft.NetLib.Security.Certificates --version 1.0.0.5
                    
NuGet\Install-Package Eigenverft.NetLib.Security.Certificates -Version 1.0.0.5
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Eigenverft.NetLib.Security.Certificates" Version="1.0.0.5" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Eigenverft.NetLib.Security.Certificates" Version="1.0.0.5" />
                    
Directory.Packages.props
<PackageReference Include="Eigenverft.NetLib.Security.Certificates" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Eigenverft.NetLib.Security.Certificates --version 1.0.0.5
                    
#r "nuget: Eigenverft.NetLib.Security.Certificates, 1.0.0.5"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Eigenverft.NetLib.Security.Certificates@1.0.0.5
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Eigenverft.NetLib.Security.Certificates&version=1.0.0.5
                    
Install as a Cake Addin
#tool nuget:?package=Eigenverft.NetLib.Security.Certificates&version=1.0.0.5
                    
Install as a Cake Tool

Eigenverft.NetLib.Security.Certificates

NuGet Version NuGet Downloads Repository CI Targets License

Create self-signed X.509 certificates and load PFX files with an explicit, policy-controlled recovery behavior.

✨ At a glance

Capability What it does Starting point
Self-signed certificates Create certificates for TLS, code signing, or email protection with RSA or ECDSA profiles SelfSignedCertificateFactory.Create(...)
Managed PFX files Load a valid certificate or return a generated recovery certificate ManagedCertificateFile.LoadOrCreate(...)
Recovery policy Control whether recovery material is kept in memory or persisted CertificateRecoveryMode

📦 Installation

dotnet add package Eigenverft.NetLib.Security.Certificates

🚀 Quick start

Load a managed certificate and generate a replacement only when the PFX is missing or expired:

using System;
using System.IO;
using System.Security.Cryptography.X509Certificates;
using Eigenverft.NetLib.Security.Certificates;

string password = Environment.GetEnvironmentVariable("APP_PFX_PASSWORD")
    ?? throw new InvalidOperationException("APP_PFX_PASSWORD is required.");

ManagedCertificateResult managed = ManagedCertificateFile.LoadOrCreate(
    new ManagedCertificateFileOptions
    {
        FilePath = Path.Combine(AppContext.BaseDirectory, "certs", "worker.pfx"),
        Password = password,
        RecoveryMode = CertificateRecoveryMode.ReplaceExpired,
        Replacement = new SelfSignedCertificateOptions
        {
            Subject = new CertificateSubject { CommonName = "worker.example" },
            Purpose = CertificatePurpose.TlsServer,
            DnsNames = new[] { "worker.example" },
        },
    });

using X509Certificate2 certificate = managed.Certificate;
Console.WriteLine($"{managed.Action}; persisted: {managed.Persisted}");

ManagedCertificateResult.Certificate is caller-owned and must be disposed. Use SelfSignedCertificateFactory.Create(...) directly when the application does not need a managed-file lifecycle.

🔐 Certificate and recovery behavior

SelfSignedCertificateFactory supports TLS server/client, code-signing, and email-protection purposes. Profiles include RSA 2048/3072 with SHA-256 and ECDSA P-256/SHA-256 or P-384/SHA-384. TLS server certificates require at least one DNS or IP subject alternative name.

PreserveExisting is the default recovery mode: a generated certificate is returned in memory, and the configured PFX path is not created or replaced. ReplaceExpired creates a missing PFX and replaces only an existing, successfully imported expired PFX. ReplaceAnyUnusable can overwrite existing files that fail import, password, read, or access checks, so it must not be used casually with externally managed credentials. None disables recovery and requires an existing, currently valid PFX with a private key.

Self-signed certificates are not automatically trusted by clients. Protect the PFX path and password using the application's deployment controls; this library does not configure filesystem ACLs or establish a certificate trust chain.

The WebLib Kestrel.Sni package consumes these certificate helpers for configuration-driven SNI certificates; this package does not depend on Kestrel or ASP.NET Core. Hosting.DirectoryLayout offers a conventional AppCerts path, but certificate loading accepts an explicit file path. Machine binding and Data Protection are separate value/key-ring mechanisms: neither is applied automatically to PFX files by this package.

🎯 Target frameworks

  • net8.0
  • net10.0

📄 License

MIT

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.
  • net8.0

    • No dependencies.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Eigenverft.NetLib.Security.Certificates:

Package Downloads
Eigenverft.WebLib.Kestrel.Sni

Configuration-driven Kestrel listeners with SNI certificate selection, TLS policy, and certificate recovery.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0.5 25 9/29/2026
1.0.0.4 45 9/28/2026
1.0.0.3 133 9/12/2026

Initial capability package extracted from Eigenverft.NetLib.Infrastructure.