./security/cfssl, CloudFlare PKI toolkit

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 1.7.0, Package name: cfssl-1.7.0, Maintainer: iquiw

CFSSL is CloudFlare's PKI/TLS swiss army knife. It is both a command line
tool and an HTTP API server for signing, verifying, and bundling TLS
certificates. It requires Go 1.16+ to build.

Note that certain linux distributions have certain algorithms removed
(RHEL-based distributions in particular), so the golang from the official
repositories will not work. Users of these distributions should install go
manually to install CFSSL.

CFSSL consists of:

* a set of packages useful for building custom TLS PKI tools
* the cfssl program, which is the canonical command line utility using the
CFSSL packages.
* the multirootca program, which is a certificate authority server that can
use multiple signing keys.
* the mkbundle program is used to build certificate pool bundles.
* the cfssljson program, which takes the JSON output from the cfssl and
multirootca programs and writes certificates, keys, CSRs, and bundles
to disk.


Master sites:

Filesize: 7628.619 KB

Version history: (Expand)


CVS history: (Expand)


   2026-10-04 11:22:10 by Iku Iwasa | Files touched by this commit (3) | Package updated
Log message:
cfssl: update to 1.7.0

* Add scripts to regenerate {api,bundler,ubiquity}'s testdata
* Create semgrep.yml
* Fixes #1237 partially by updating test data certificates to be valid
* Github actions linter uses golangci-lint@v1.57
* Migrate goreleaser config to v2 and limit build parallelism
* Regenerate api's testdata
* Regenerate bundler's testdata
* Regenerate ubiquity's testdata
* Revert "Upgrade certificate-transparency-go from v1.1.8 to v1.3.1"
* SECENG-13957: feat: add ML-DSA-44/65/87 post-quantum key support
* Update README
* Update READMe
* Update certstore_development and sqlit_test dbs after testdata update
* Update repository to reflect required min go version of 1.20
* Update semgrep.yml
* Upgrade certificate-transparency-go from v1.1.8 to v1.3.1
* build(deps): bump github.com/go-sql-driver/mysql from 1.7.1 to 1.8.0
* build(deps): bump github.com/google/certificate-transparency-go
* build(deps): bump golang.org/x/crypto from 0.19.0 to 0.21.0
* fix: preserve regenerated fixture coverage
* fix: prevent CSR extensions from overriding CA-managed key usage in copy_extensions
* ignore .git to .dockerignore
   2026-09-05 21:10:06 by Benny Siegert | Files touched by this commit (222) | Package updated
Log message:
Revbump all Go packages after go127 update
   2026-08-31 21:19:11 by Benny Siegert | Files touched by this commit (222)
Log message:
Revbump all Go packages after go127 became the default
   2026-08-22 17:19:19 by Benny Siegert | Files touched by this commit (211) | Package updated
Log message:
Revbump all Go packages after go126 update
   2026-08-15 14:53:40 by Benny Siegert | Files touched by this commit (211) | Package updated
Log message:
Revbump all Go packages after Go 1.26 update
   2026-07-08 20:32:45 by Benny Siegert | Files touched by this commit (208) | Package updated
Log message:
Revbump all Go packages after go126 update
   2026-06-05 12:21:56 by Benny Siegert | Files touched by this commit (205) | Package updated
Log message:
Revbump all Go packages after go126 security update
   2026-05-07 20:50:12 by Benny Siegert | Files touched by this commit (204) | Package updated
Log message:
Revbump all Go packages after go126 security update