FluentCertificates.Extensions
0.10.0
dotnet add package FluentCertificates.Extensions --version 0.10.0
NuGet\Install-Package FluentCertificates.Extensions -Version 0.10.0
<PackageReference Include="FluentCertificates.Extensions" Version="0.10.0" />
paket add FluentCertificates.Extensions --version 0.10.0
#r "nuget: FluentCertificates.Extensions, 0.10.0"
// Install FluentCertificates.Extensions as a Cake Addin #addin nuget:?package=FluentCertificates.Extensions&version=0.10.0 // Install FluentCertificates.Extensions as a Cake Tool #tool nuget:?package=FluentCertificates.Extensions&version=0.10.0
📖 FluentCertificates Overview
⚠️ Note: while version numbers are v0.x.y, this software is under initial development and there'll be breaking-changes in its API from version to version.
FluentCertificates is a library using the Immutable Fluent Builder pattern for easily creating, finding and exporting certificates. Makes it simple to generate your own certificate chains, or just stand-alone self-signed certificates.
This project is published in several NuGet packages:
- FluentCertificates: Top-level package that doesn't introduce any new functionality, it just imports the FluentCertificates.Builder, FluentCertificates.Extensions and FluentCertificates.Finder packages.
- FluentCertificates.Builder: Provides
CertificateBuilder
for building certificates and also includes a bunch of convenient extension-methods. Examples below - FluentCertificates.Extensions: Provides a bunch of convenient extension-methods. Examples below
- FluentCertificates.Finder: Provides
CertificateFinder
for finding certificates across a collection of X509Stores. Examples below
Unfortunately documentation is incomplete. You may find more examples within the project's unit tests.
CertificateBuilder
examples
CertificateBuilder
requires the FluentCertificates.Builder package and is found under the FluentCertificates
namespace.
The absolute minimum needed to create a certificate (although it may not be a very useful one):
using var cert = new CertificateBuilder().Create();
Create a CertificateSigningRequest
for signing, exporting and passing to a 3rd party CA:
//A public & private keypair must be created first, outside of the CertificateBuilder, otherwise you'd have no way to retrieve the private-key used for the new CertificateSigningRequest object
using var keys = RSA.Create();
//Creating a CertificateSigningRequest
var csr = new CertificateBuilder()
.SetUsage(CertificateUsage.Server)
.SetSubject(b => b.SetCommonName("*.fake.domain"))
.SetDnsNames("*.fake.domain", "fake.domain")
.SetKeyPair(keys)
.CreateCertificateSigningRequest();
//The CertificateRequest object is accessible here:
var certRequest = csr.CertificateRequest;
//CSR can be exported to a string
Console.WriteLine(csr.ToPemString());
//Or to a file or StringWriter instance
csr.ExportAsPem("csr.pem");
Build a self-signed web server certificate:
//Using a fluent style
using var cert = new CertificateBuilder()
.SetUsage(CertificateUsage.Server)
.SetFriendlyName("Example self-signed web-server certificate")
.SetSubject(b => b.SetCommonName("*.fake.domain"))
.SetDnsNames("*.fake.domain", "fake.domain")
.SetNotAfter(DateTimeOffset.UtcNow.AddMonths(1))
.Create();
//And just to demonstrate using object initializers (I'll use fluent style from now on though)
using var builder = new CertificateBuilder() {
Usage = CertificateUsage.Server,
FriendlyName = "Example self-signed web-server certificate",
Subject = new X500NameBuilder().SetCommonName("*.fake.domain"),
DnsNames = new[] { "*.fake.domain", "fake.domain" },
NotAfter = DateTimeOffset.UtcNow.AddMonths(1)
};
var cert = builder.Create();
Build a CA (certificate authority):
//A CA's expiry date must be later than that of any certificates it will issue
using var issuer = new CertificateBuilder()
.SetUsage(CertificateUsage.CA)
.SetFriendlyName("Example root CA")
.SetSubject(b => b.SetCommonName("Example root CA"))
.SetNotAfter(DateTimeOffset.UtcNow.AddYears(100))
.Create();
Build a client-auth certificate signed by a CA:
//Note: the 'issuer' certificate used must have a private-key attached in order to sign this new certificate
using var cert = new CertificateBuilder()
.SetUsage(CertificateUsage.Client)
.SetFriendlyName("Example client-auth certificate")
.SetSubject(b => b.SetCommonName("User: Michael"))
.SetNotAfter(DateTimeOffset.UtcNow.AddYears(1))
.SetIssuer(issuer)
.Create();
Advanced: Build a certificate with customized extensions:
using var cert = new CertificateBuilder()
.SetFriendlyName("Example certificate with customized extensions")
.SetSubject(b => b.SetCommonName("Example certificate with customized extensions"))
.AddExtension(new X509BasicConstraintsExtension(false, false, 0, true))
.AddExtension(new X509KeyUsageExtension(X509KeyUsageFlags.DigitalSignature | X509KeyUsageFlags.KeyEncipherment | X509KeyUsageFlags.DataEncipherment, true))
.AddExtension(new X509EnhancedKeyUsageExtension(new OidCollection { new(KeyPurposeID.AnyExtendedKeyUsage.Id) }, false))
.SetIssuer(issuer)
.Create();
CertificateFinder
examples
CertificateFinder
requires the FluentCertificates.Finder package and is found under the FluentCertificates
namespace.
TODO: document this
X500NameBuilder
examples
X500NameBuilder
requires the FluentCertificates.Builder package and is found under the FluentCertificates
namespace.
TODO: document this; see unit tests for more examples
X509Certificate2
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
TODO: document these; see unit tests for more examples
Extension-Method | Description |
---|---|
BuildChain |
|
ExportAsCert |
|
ExportAsPkcs12 |
|
ExportAsPkcs7 |
|
ExportAsPem |
|
ToPemString |
|
ToBase64String |
|
GetPrivateKey |
|
GetSignatureData |
|
GetToBeSignedData |
|
IsValidNow |
|
IsValid |
|
IsSelfSigned |
|
IsIssuedBy |
X509Chain
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
TODO: document these
Extension-Method | Description |
---|---|
ToCollection |
|
ToEnumerable |
|
ExportAsPkcs7 |
|
ExportAsPkcs12 |
|
ExportAsPem |
|
ToPemString |
X509Certificate2Collection
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
TODO: document these
Extension-Method | Description |
---|---|
ToEnumerable |
|
ExportAsPkcs7 |
|
ExportAsPkcs12 |
|
ExportAsPem |
|
ToPemString |
IEnumerable<X509Certificate2>
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
TODO: document these
Extension-Method | Description |
---|---|
ToCollection |
|
FilterPrivateKeys |
|
ExportAsPkcs7 |
|
ExportAsPkcs12 |
|
ExportAsPem |
|
ToPemString |
AsymmetricAlgorithm
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
TODO: document these
Extension-Method | Description |
---|---|
ToPrivateKeyPemString |
|
ToPublicKeyPemString |
|
ExportAsPrivateKeyPem |
|
ExportAsPublicKeyPem |
CertificateRequest
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
Extension-Method | Description |
---|---|
ToPemString() |
Exports the CertificateRequest to a PEM string. |
ExportAsPem(string path) |
Exports the CertificateRequest to the specified PEM file. |
ExportAsPem(TextWriter writer) |
Exports the CertificateRequest in PEM format to the given TextWriter . |
ConvertToBouncyCastle() |
Converts the CertificateRequest to a BouncyCastle Pkcs10CertificationRequest |
X509Extension
extension-methods
These extension methods require the FluentCertificates.Builder package and are found under the FluentCertificates
namespace.
Extension-Method | Description |
---|---|
dnExtension.ConvertToBouncyCastle() |
Converts a DotNet X509Extension to a BouncyCastle X509Extension . |
bcExtension.ConvertToDotNet(string oid) |
Converts a BouncyCastle X509Extension to a DotNet X509Extension . A DotNet X509Extension includes an OID, but a BouncyCastle one doesn't, therefore one must be supplied in the parameters here. |
bcExtension.ConvertToDotNet(DerObjectIdentifier oid) |
Converts a BouncyCastle X509Extension to a DotNet X509Extension . A DotNet X509Extension includes an OID, but a BouncyCastle one doesn't, therefore one must be supplied in the parameters here. |
Product | Versions Compatible and additional computed target framework versions. |
---|---|
.NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. |
-
net8.0
- SideData (>= 0.1.0)
- System.Collections.Immutable (>= 9.0.0)
NuGet packages (2)
Showing the top 2 NuGet packages that depend on FluentCertificates.Extensions:
Package | Downloads |
---|---|
FluentCertificates.Builder
FluentCertificates.Builder is part of the FluentCertificates package. This library uses the Immutable Fluent Builder pattern for easily creating and exporting certificates. |
|
FluentCertificates
FluentCertificates is a library using the Immutable Fluent Builder pattern for easily creating, finding/querying and exporting certificates. |
GitHub repositories
This package is not used by any popular GitHub repositories.
Version | Downloads | Last updated |
---|---|---|
0.10.0 | 0 | 11/28/2024 |
0.9.2-ci0009 | 0 | 11/28/2024 |
0.9.2-ci0008 | 0 | 11/28/2024 |
0.9.2-ci0006 | 29 | 11/27/2024 |
0.9.2-ci0004 | 26 | 11/27/2024 |
0.9.2-ci0002 | 147 | 2/19/2024 |
0.9.1 | 3,478 | 8/11/2023 |
0.9.1-ci0017 | 236 | 8/11/2023 |
0.9.1-ci0007 | 233 | 8/11/2023 |
0.9.1-ci0006 | 258 | 8/11/2023 |
0.9.0 | 284 | 8/10/2023 |
0.8.1-ci0031 | 254 | 8/10/2023 |
0.8.1-ci0028 | 246 | 8/2/2023 |
0.8.1-ci0027 | 257 | 8/2/2023 |
0.8.1-ci0025 | 241 | 8/2/2023 |
0.8.1-ci0020 | 286 | 8/1/2023 |
0.8.1-ci0018 | 243 | 8/1/2023 |
0.8.1-ci0016 | 219 | 8/1/2023 |
0.8.0 | 2,594 | 7/7/2022 |
0.7.2-ci0010 | 303 | 7/7/2022 |
0.7.2-ci0002 | 320 | 7/6/2022 |
0.7.2-ci0001 | 285 | 7/6/2022 |
0.7.1 | 940 | 6/24/2022 |
0.7.1-ci0001 | 264 | 6/24/2022 |
0.7.0 | 973 | 6/24/2022 |
0.6.1-ci0002 | 293 | 6/24/2022 |
0.6.1-ci0001 | 253 | 6/24/2022 |
0.6.0 | 956 | 6/23/2022 |
0.5.5-ci0009 | 269 | 6/23/2022 |
0.5.5-ci0008 | 256 | 6/23/2022 |
0.5.5-ci0007 | 271 | 6/23/2022 |
0.5.5-ci0006 | 274 | 6/23/2022 |
0.5.5-ci0005 | 256 | 6/23/2022 |
0.5.5-ci0004 | 293 | 6/21/2022 |