Sign inSign up

trustedtech/docker-pkid-web

By trustedtech

•Updated 4 months ago

Image
Networking
Security
Web servers
0

344

trustedtech/docker-pkid-web repository overview

MyCA icon

⁠trustedtech/docker-pkid-web

Container image for PKId Web (pkid-web), the HTTPS web interface for the MyCA PKI stack. It presents the browser UI for certificate operations and talks to the PKId daemon (pkid), which holds the CA data and issues X.509⁠ certificates.

MyCA is a multi-platform PKIX implementation (Windows and Linux) for CA workflows. PKId Web is the component that exposes this PKI through HTTP over TLS to web clients. Visit MyCA home page⁠ or refer to the documentation⁠ for more details.

⁠What this image provides

PKId Web:

  • Serves the web UI for PKI administration and end-user flows (over HTTPS by default).
  • Connects to pkid using TLS client credentials configured for your deployment (client-certificate, client-private-key, and related settings in the product documentation).
  • Supports Docker-oriented operation via the docker-mode configuration setting (see Configuration - PKId Web in the MyCA help).

Together with trustedtech/docker-pkid and the rest of MyCA (pkiadmin, language bindings), you get full certificate lifecycle capabilities described in the official docs: issuance, retrieval in multiple formats, revocation, re-granting, deletion, audit trails, and optional TSA usage where your deployment includes it.

Note:
In order to run the PKId Web server in a container you need to build your own image and generate all necessary configuration files, certificates, private keys and initialize the database. There is a set of build scripts for Windows⁠ and for Linux⁠ that can help you with this process. Please refer to the MyCA documentation⁠ for more details.

⁠Networking

  • Web UI (HTTPS): by default PKId Web listens on TCP port 443 (listen-port). The default bind address is all interfaces (listen-address default *).
  • Backend PKId: PKId Web reaches pkid at pkid.address (default ::1) and pkid.port (default 33334).

Typical Docker usage: publish the web port and ensure the pkid service is reachable at the address/port your configuration uses (often a user-defined network and service name instead of ::1).

Example shape (adjust names, TLS mounts, and config to match your setup):

docker network create myca-net
docker run -d --name pkid --network myca-net trustedtech/docker-pkid:<tag>
docker run -d --name pkid-web --network myca-net -p 443:443 \
  trustedtech/docker-pkid-web:<tag>

You must supply server TLS material (certificate, private-key, ca-chain, etc.) and client TLS material for connecting to pkid, as documented under Configuration - PKId Web.

⁠Configuration

The authoritative list of settings is Configuration - PKId Web in the English HTML help (en/configuration_pkid_web.html). Highlights for containers:

  • listen-port / listen-address — where the web server listens.
  • pkid.port / pkid.address — how PKId Web finds pkid.
  • docker-mode — enable for Docker-style deployments.
  • TLS paths — certificate, private-key, ca-chain, client-certificate, client-private-key, optional passphrase settings.
  • CORS / domain — e.g. domain, access-allow-origin, trust flags for proxies and local clients.

Command-line options for the pkid-web binary are documented under Command Line - PKId Web (en/command_line_pkid_web.html). Some options have environment variable equivalents; where both are set, the environment variable takes precedence.

Optional database logging uses --db-type, --db-conn (or MYCA_DB_CONN_STRING), and related ODBC settings on UNIX (MYCA_ODBC_INST / odbcinst).

The PKId daemon image is trustedtech/docker-pkid. Deploy pkid first (or alongside) so PKId Web has a working backend.

⁠Documentation

English topics ship with MyCA (HTML under the en folder), including:

  • Overview — MyCA product scope
  • Configuration - PKId Web / Command Line - PKId Web
  • PKId command line and configuration (backend)
  • Certificate management, FAQ, and client libraries

⁠Tags and versions

Image tags follow the published MyCA / PKId Web release (for example 1.0.0). See this repository’s tags on Docker Hub for the current line.

MyCA and PKId Web are copyright Mariusz Drozdowski. This overview summarizes behavior described in the official MyCA documentation; see the distributed license topic in the help set for terms that apply to the software.

Tag summary

Content type

Image

Digest

sha256:8abe1f248…

Size

112.6 MB

Last updated

4 months ago

docker pull trustedtech/docker-pkid-web