From a32132348dfc54199c89ed5adac8b5abaa67124f Mon Sep 17 00:00:00 2001 From: A R R R Associates Date: Fri, 11 Sep 2026 11:59:03 +0530 Subject: [PATCH] Add GST operator agent localhost certificate generator --- .../generate_localhost_cert.py | 59 +++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 app/modules/accounting/gst_operator_agent_runtime/generate_localhost_cert.py diff --git a/app/modules/accounting/gst_operator_agent_runtime/generate_localhost_cert.py b/app/modules/accounting/gst_operator_agent_runtime/generate_localhost_cert.py new file mode 100644 index 0000000..4463a9d --- /dev/null +++ b/app/modules/accounting/gst_operator_agent_runtime/generate_localhost_cert.py @@ -0,0 +1,59 @@ +from __future__ import annotations + +import ipaddress +from datetime import datetime, timedelta, timezone +from pathlib import Path + +from cryptography import x509 +from cryptography.hazmat.primitives import hashes, serialization +from cryptography.hazmat.primitives.asymmetric import rsa +from cryptography.x509.oid import NameOID + +ROOT = Path(__file__).resolve().parent +CERT_PEM = ROOT / "localhost-cert.pem" +KEY_PEM = ROOT / "localhost-key.pem" +CERT_DER = ROOT / "localhost-cert.cer" + + +def main() -> None: + key = rsa.generate_private_key(public_exponent=65537, key_size=2048) + name = x509.Name([ + x509.NameAttribute(NameOID.COMMON_NAME, "ARRR GST Operator Agent localhost"), + x509.NameAttribute(NameOID.ORGANIZATION_NAME, "ARRR & Associates"), + ]) + now = datetime.now(timezone.utc) + cert = ( + x509.CertificateBuilder() + .subject_name(name) + .issuer_name(name) + .public_key(key.public_key()) + .serial_number(x509.random_serial_number()) + .not_valid_before(now - timedelta(days=1)) + .not_valid_after(now + timedelta(days=825)) + .add_extension( + x509.SubjectAlternativeName([ + x509.DNSName("localhost"), + x509.IPAddress(ipaddress.ip_address("127.0.0.1")), + ]), + critical=False, + ) + .add_extension(x509.BasicConstraints(ca=False, path_length=None), critical=True) + .add_extension( + x509.ExtendedKeyUsage([x509.oid.ExtendedKeyUsageOID.SERVER_AUTH]), + critical=False, + ) + .sign(key, hashes.SHA256()) + ) + KEY_PEM.write_bytes( + key.private_bytes( + encoding=serialization.Encoding.PEM, + format=serialization.PrivateFormat.TraditionalOpenSSL, + encryption_algorithm=serialization.NoEncryption(), + ) + ) + CERT_PEM.write_bytes(cert.public_bytes(serialization.Encoding.PEM)) + CERT_DER.write_bytes(cert.public_bytes(serialization.Encoding.DER)) + + +if __name__ == "__main__": + main()