| name | mtls-pki-management |
| description | mTLS PKI Management establishes and maintains a Public Key Infrastructure Use when this capability is needed. |
| metadata | {"author":"amnadtaowsoam"} |
Mtls Pki Management
Skill Profile
(Select at least one profile to enable specific modules)
Overview
mTLS PKI Management establishes and maintains a Public Key Infrastructure for mutual TLS authentication, managing certificate issuance, renewal, revocation, and trust relationships across IoT devices and services at enterprise scale.
Why This Matters
Core Concepts & Rules
1. Core Principles
- Follow established patterns and conventions
- Maintain consistency across codebase
- Document decisions and trade-offs
2. Implementation Guidelines
- Start with the simplest viable solution
- Iterate based on feedback and requirements
- Test thoroughly before deployment
Inputs / Outputs / Contracts
- Inputs:
- <e.g., env vars, request payload, file paths, schema>
- Entry Conditions:
- <Pre-requisites: e.g., Repo initialized, DB running, specific branch checked out>
- Outputs:
- <e.g., artifacts (PR diff, docs, tests, dashboard JSON)>
- Artifacts Required (Deliverables):
- <e.g., Code Diff, Unit Tests, Migration Script, API Docs>
- Acceptance Evidence:
- <e.g., Test Report (screenshot/log), Benchmark Result, Security Scan Report>
- Success Criteria:
- <e.g., p95 < 300ms, coverage ≥ 80%>
Skill Composition
- Depends on: security
- Compatible with: None
- Conflicts with: None
- Related Skills: authn, authz
Quick Start
-
Install dependencies:
pip install cryptography pyopenssl
-
Initialize PKI manager:
pki = PKIManager(
root_ca_path="root_ca.pem",
intermediate_ca_path="intermediate_ca.pem"
)
-
Generate key pair:
private_key, public_key = pki.generate_key_pair(
key_type=KeyType.ECC
)
-
Issue certificate:
cert = pki.issue_certificate(csr, issuer_key, issuer_cert, 365, key_usage, eku)
Assumptions / Constraints / Non-goals
- Assumptions:
- Development environment is properly configured
- Required dependencies are available
- Team has basic understanding of domain
- Constraints:
- Must follow existing codebase conventions
- Time and resource limitations
- Compatibility requirements
- Non-goals:
- This skill does not cover edge cases outside scope
- Not a replacement for formal training
Compatibility & Prerequisites
- Supported Versions:
- Python 3.8+
- Node.js 16+
- Modern browsers (Chrome, Firefox, Safari, Edge)
- Required AI Tools:
- Code editor (VS Code recommended)
- Testing framework appropriate for language
- Version control (Git)
- Dependencies:
- Language-specific package manager
- Build tools
- Testing libraries
- Environment Setup:
.env.example keys: API_KEY, DATABASE_URL (no values)
Test Scenario Matrix (QA Strategy)
| Type | Focus Area | Required Scenarios / Mocks |
|---|
| Unit | Core Logic | Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |
| Integration | DB / API | All external API calls or database connections must be mocked during unit tests |
| E2E | User Journey | Critical user flows to test |
| Performance | Latency / Load | Benchmark requirements |
| Security | Vuln / Auth | SAST/DAST or dependency audit |
| Frontend | UX / A11y | Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |
Technical Guardrails & Security Threat Model
1. Security & Privacy (Threat Model)
- Top Threats: Injection attacks, authentication bypass, data exposure
2. Performance & Resources
3. Architecture & Scalability
4. Observability & Reliability
Agent Directives & Error Recovery
(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)
- Thinking Process: Analyze root cause before fixing. Do not brute-force.
- Fallback Strategy: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.
- Self-Review: Check against Guardrails & Anti-patterns before finalizing.
- Output Constraints: Output ONLY the modified code block. Do not explain unless asked.
Definition of Done (DoD) Checklist
Anti-patterns
-
Manual Certificate Management: Manual issuance and renewal
- Why it's bad: Doesn't scale, high error rate
- Solution: Implement automated PKI management
-
No Revocation Checking: Not checking certificate revocation status
- Why it's bad: Accepts revoked certificates
- Solution: Implement CRL/OCSP checking
-
Long Certificate Validity: Certificates valid for 5+ years
- Why it's bad: Increases exposure if compromised
- Solution: Use 1-2 year validity with auto-renewal
-
Weak Cryptography: Using weak algorithms or key sizes
- Why it's bad: Vulnerable to attacks
- Solution: Use minimum 2048-bit RSA or 256-bit ECC
Reference Links & Examples
- Internal documentation and examples
- Official documentation and best practices
- Community resources and discussions
Versioning & Changelog
- Version: 1.0.0
- Changelog:
- 2026-02-22: Initial version with complete template structure
Converted and distributed by TomeVault — claim your Tome and manage your conversions.