Flatsonar

XCA

by Christian Hohnstädt

X Certificate and Key management

Broad permissions Verified creator BSD-3-Clause v2.9.0
Screenshot 1 of XCA Screenshot 2 of XCA

About

XCA is intended for creating and managing X.509 certificates, certificate requests, RSA, DSA and EC private keys, Smartcards and CRLs. Everything that is needed for a CA is implemented. All CAs can sign sub-CAs recursively. These certificate chains are shown clearly. For an easy company-wide use there are customiseable templates that can be used for certificate or request generation.

Features:

  • Start your own PKI and create all kinds of private keys, certificates, requests or CRLs
  • Import and export them in any format like PEM, DER, PKCS#7, PKCS#12
  • Use them for your IPsec, OpenVPN, TLS or any other certificate based setup
  • Manage your Smart-Cards via PKCS#11 interface
  • Export certificates and requests as OpenSSL config file
  • Create Subject- and/or Extension- templates to ease issuing similar certs
  • Convert existing certificates or requests to templates
  • Get the broad support of x509v3 extensions as flexible as OpenSSL but user friendlier
  • Adapt the columns to have your important information at a glance

Permissions

3 permissions weaken the sandbox. Flatsonar asks before installing.

  • X11 display: X11 lets apps read input and windows of other apps
    --socket=x11
  • smart card readers
    --socket=pcsc
  • full access to your home folder
    --filesystem=home
  • network
    --share=network
  • inter-process communication (needed for X11)
    --share=ipc
  • Wayland display
    --socket=wayland
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • GPU acceleration
    --device=dri
  • access to xdg-config/kdeglobals
    --filesystem=xdg-config/kdeglobals:ro
  • talks to com.canonical.AppMenu.Registrar
    --talk-name=com.canonical.AppMenu.Registrar
  • talks to org.kde.kconfig.notify
    --talk-name=org.kde.kconfig.notify
  • talks to org.kde.KGlobalSettings
    --talk-name=org.kde.KGlobalSettings

Who publishes this

The creator demonstrably controls this app id: Flathub verification, the hosting account owns the namespace, or a well-known file on their domain.

  • verified on Flathub: the developer proved they control this app id
    publisher:flathub

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.