344
Container image for PKId Web (pkid-web), the HTTPS web interface for the MyCA PKI stack. It presents the browser UI for certificate operations and talks to the PKId daemon (pkid), which holds the CA data and issues X.509 certificates.
MyCA is a multi-platform PKIX implementation (Windows and Linux) for CA workflows. PKId Web is the component that exposes this PKI through HTTP over TLS to web clients. Visit MyCA home page or refer to the documentation for more details.
PKId Web:
client-certificate, client-private-key, and related settings in the product documentation).docker-mode configuration setting (see Configuration - PKId Web in the MyCA help).Together with trustedtech/docker-pkid and the rest of MyCA (pkiadmin, language bindings), you get full certificate lifecycle capabilities described in the official docs: issuance, retrieval in multiple formats, revocation, re-granting, deletion, audit trails, and optional TSA usage where your deployment includes it.
Note:
In order to run the PKId Web server in a container you need to build your own image and generate all necessary configuration files, certificates, private keys and initialize the database. There is a set of build scripts for Windows and for Linux that can help you with this process. Please refer to the MyCA documentation for more details.
listen-port). The default bind address is all interfaces (listen-address default *).pkid.address (default ::1) and pkid.port (default 33334).Typical Docker usage: publish the web port and ensure the pkid service is reachable at the address/port your configuration uses (often a user-defined network and service name instead of ::1).
Example shape (adjust names, TLS mounts, and config to match your setup):
docker network create myca-net
docker run -d --name pkid --network myca-net trustedtech/docker-pkid:<tag>
docker run -d --name pkid-web --network myca-net -p 443:443 \
trustedtech/docker-pkid-web:<tag>
You must supply server TLS material (certificate, private-key, ca-chain, etc.) and client TLS material for connecting to pkid, as documented under Configuration - PKId Web.
The authoritative list of settings is Configuration - PKId Web in the English HTML help (en/configuration_pkid_web.html). Highlights for containers:
listen-port / listen-address — where the web server listens.pkid.port / pkid.address — how PKId Web finds pkid.docker-mode — enable for Docker-style deployments.certificate, private-key, ca-chain, client-certificate, client-private-key, optional passphrase settings.domain, access-allow-origin, trust flags for proxies and local clients.Command-line options for the pkid-web binary are documented under Command Line - PKId Web (en/command_line_pkid_web.html). Some options have environment variable equivalents; where both are set, the environment variable takes precedence.
Optional database logging uses --db-type, --db-conn (or MYCA_DB_CONN_STRING), and related ODBC settings on UNIX (MYCA_ODBC_INST / odbcinst).
The PKId daemon image is trustedtech/docker-pkid. Deploy pkid first (or alongside) so PKId Web has a working backend.
English topics ship with MyCA (HTML under the en folder), including:
Image tags follow the published MyCA / PKId Web release (for example 1.0.0). See this repository’s tags on Docker Hub for the current line.
MyCA and PKId Web are copyright Mariusz Drozdowski. This overview summarizes behavior described in the official MyCA documentation; see the distributed license topic in the help set for terms that apply to the software.
Content type
Image
Digest
sha256:8abe1f248…
Size
112.6 MB
Last updated
4 months ago
docker pull trustedtech/docker-pkid-web