SkillAgentSearch skills...

configuring-certificate-authority-with-openssl

Build a two-tier PKI Certificate Authority hierarchy (offline Root CA

Install / Use

npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-certificate-authority-with-openssl

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

88/100

Category

Security

Supported Platforms

Universal

Our assessment of configuring-certificate-authority-with-openssl

configuring-certificate-authority-with-openssl scores 88/100 on our quality scale, 295th of 544 Security skills we index.

Its SKILL.md is 3.4 KB long, well organised into 10 sections with 1 code example: a solid amount of guidance for an agent.

With 33,340 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
17/20
Description
12/15
Adoption
19/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 25 days ago, so configuring-certificate-authority-with-openssl is actively maintained.
  • It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-09-26. Automated pattern scan on 2026-09-25. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

configuring-certificate-authority-with-openssl compared with similar skills

All 4 of these similar skills score higher than configuring-certificate-authority-with-openssl; compare them before choosing.

SkillScoreStarsUpdatedFormat
configuring-certificate-authority-with-openssl (this skill)by mukul9758833.3k25d agoSKILL.md
Agent-Reachby Panniantong10085.4k10d agoCLAUDE.md
headroomby headroomlabs-ai10073.8ktodayCLAUDE.md
Scraplingby D4Vinci10083.7ktodayMCP Server
algorithmic-artby anthropics100177.9k3d agoSKILL.md

Frequently asked questions

How do I install configuring-certificate-authority-with-openssl?
Run npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill configuring-certificate-authority-with-openssl. The install tabs above show the steps for each supported agent.
Which AI agents does configuring-certificate-authority-with-openssl work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is configuring-certificate-authority-with-openssl safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is configuring-certificate-authority-with-openssl still maintained?
The repository was last updated 25 days ago, so configuring-certificate-authority-with-openssl is actively maintained.

name: configuring-certificate-authority-with-openssl description: Build a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering certificate extensions, CRL distribution points, OCSP responder configuration, and certificate policy management. Use when standing up an internal CA, issuing or revoking X.509 certificates, or designing PKI trust hierarchies for TLS, code-signing, or client-authentication use cases. domain: cybersecurity subdomain: cryptography tags:

  • cryptography
  • pki
  • certificate-authority
  • openssl
  • x509 version: '1.0' author: mahipal license: Apache-2.0 nist_csf:
  • PR.DS-01
  • PR.DS-02
  • PR.DS-10 mitre_attack:
  • T1649
  • T1553.004
  • T1557
  • T1587.003

Configuring Certificate Authority with OpenSSL

Overview

A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA + Intermediate CA) using OpenSSL and the Python cryptography library, including CRL distribution, OCSP responder configuration, and certificate policy management.

When to Use

  • When deploying or configuring configuring certificate authority with openssl capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with cryptography concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Create a Root CA with self-signed certificate
  • Create an Intermediate CA signed by the Root CA
  • Issue server and client certificates from the Intermediate CA
  • Configure Certificate Revocation Lists (CRLs)
  • Implement certificate policies and constraints
  • Build a complete PKI hierarchy programmatically

Key Concepts

CA Hierarchy

Root CA (offline, air-gapped)
  |
  +-- Intermediate CA (online, operational)
        |
        +-- Server Certificates
        +-- Client Certificates
        +-- Code Signing Certificates

Certificate Extensions

| Extension | Purpose | Critical | |-----------|---------|----------| | basicConstraints | CA:TRUE/FALSE, pathLenConstraint | Yes | | keyUsage | keyCertSign, cRLSign, digitalSignature | Yes | | extendedKeyUsage | serverAuth, clientAuth, codeSigning | No | | subjectKeyIdentifier | Hash of public key | No | | authorityKeyIdentifier | Issuer's key identifier | No | | crlDistributionPoints | URL to CRL | No | | authorityInfoAccess | OCSP responder URL | No |

Security Considerations

  • Root CA private key must be stored offline (air-gapped HSM)
  • Use minimum 4096-bit RSA or P-384 ECDSA for CA keys
  • Set path length constraints on intermediate CAs
  • Implement certificate policies (OIDs)
  • Enable CRL and OCSP for revocation checking
  • Audit all certificate issuance operations

Validation Criteria

  • [ ] Root CA self-signed certificate is valid
  • [ ] Intermediate CA certificate chains to Root CA
  • [ ] Issued certificates chain to Intermediate -> Root
  • [ ] Path length constraints are enforced
  • [ ] CRL is generated and accessible
  • [ ] Revoked certificates appear in CRL
  • [ ] Certificate policies are correctly embedded

Related Skills

View on GitHub
GitHub Stars33.3k
CategorySecurity
Updated25d ago
Forks4.0k

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions