Sign inSign up

trustedtech/docker-pkid

By trustedtech

•Updated 4 months ago

Image
Networking
Security
Web servers
0

316

trustedtech/docker-pkid repository overview

MyCA icon

⁠trustedtech/docker-pkid

Container image for pkid (PKId), the PKI service daemon from MyCA — a multi-platform PKIX implementation for a certificate authority workflows on Windows and Linux. The daemon (service) holds the CA data and issues X.509⁠ certificates. Visit MyCA home page⁠ or refer to the documentation⁠ for more details.

⁠What this image provides

The pkid daemon:

  • Issues X.509 certificates and stores them (with associated private keys) in a backend SQL database
  • Can act as an OCSP responder for certificates it issued
  • Works together with pkiadmin and the MyCA client libraries (Python, PHP, Node.js, .NET) for full certificate lifecycle management

MyCA’s PKI features (as described in the product documentation) include:

  • TLS certificates for servers, users, or mail identities, with private keys
  • Retrieval of certificates and keys in several formats (e.g. PEM, PKCS#12, compressed archives)
  • Revocation, re-granting after revocation, and deletion from the server database
  • Audit information for certificate state changes
  • Optional trusted timestamping (TSA) when used as part of a full MyCA deployment

Note:
In order to run the PKId server in a container you need to build your own image and generate all necessary configuration files, certificates, private keys and initialize the database. There is a set of build scripts for Windows⁠ and for Linux⁠ that can help you with this process. Please refer to the MyCA documentation for more details.

⁠Networking

By default, PKId listens on TCP port 33334 (configurable via listen-port). The default listen address is all interfaces (listen-address default *).

Publish that port when running the container, for example:

docker run -d -p 33334:33334 --name pkid trustedtech/docker-pkid:<tag>

Adjust host port mapping if needed.

⁠Configuration and data

PKId stores PKI data in a database. Supported database types include SQLite (single file), MySQL, PostgreSQL, and ODBC, depending on your build (see the MyCA documentation for details and licensing notes on optional components).

For production use, mount persistent storage for the database file or ensure remote database connectivity matches your database.connection-string settings.

The product documentation describes a docker-mode setting for PKId (and related tools) for container-oriented deployments. Configure the daemon using the documented Configuration - PKId options (listen address/port, database, security hashes for admin/reader roles, thread limits, logging, etc.).

A companion PKId Web image is published separately as trustedtech/docker-pkid-web for the web-facing component of the same MyCA stack. Use the documentation sections PKId Web (command line and configuration) alongside PKId.

⁠Documentation

Authoritative English help topics ship with MyCA (HTML), including:

  • Overview and certificate management
  • PKId: command line and configuration
  • PKId Web, PKIAdmin, FAQ, and language bindings

Use the MyCA Table of contents / Overview as the entry point for deeper setup and security guidance.

⁠Tags and versions

Image tags follow the published MyCA / PKId release version (for example 1.0.0). Check this repository’s tags on Docker Hub for the current line.

MyCA and PKId are copyright Mariusz Drozdowski. This Docker Hub overview summarizes behavior described in the official MyCA documentation; refer to the distributed license topic in the help set for license terms that apply to the software.

Tag summary

Content type

Image

Digest

sha256:5e1ffe081…

Size

57.8 MB

Last updated

4 months ago

docker pull trustedtech/docker-pkid