mini-acme
Description
mini-acme is a self-contained mini ACME client project (RFC 8555) in pure C/CPP built on the crypery library. There are no external dependencies: all crypto algorithms are implemented from scratch inside the crypery library.
The client obtains X.509 certificates via the ACME protocol: account registration, JWS-signed requests, HTTP-01 challenge domain ownership verification, certificate issuance. Multi-domain (SAN) certificates are supported: repeat -domain (e.g. apex + www).
Modules used
- tls - base crypto layer: TLS 1.2/1.3, AES-128-GCM, SHA-256, HMAC/HKDF, RSA-2048, ECDH (P-256, X25519), X.509 certificate generation and parsing (DER/PEM)
- ssl - OpenSSL-compatible API layer over the built-in TLS: loading certificates and keys from PEM, handshake, encrypted I/O
- http - HTTP/1.1 server: routing, static serving, WebSocket, SSE, gzip compression
- url - HTTP/HTTPS client: URL parsing, request execution, redirect handling, multipart/form-data
Technologies
- C/CPP - implementation language
- crypery - pure C network stack with no external crypto dependencies (tls, ssl, http, url modules)
- Cryptography: TLS 1.2/1.3, AES-128-GCM, SHA-256, HMAC/HKDF, RSA-2048, ECDH (P-256, X25519), X.509, JWS
- MinGW/GCC (Windows), Unix-like systems
- License GNU AGPL v3 (Affero GPL)