An "incorrect password" error is received when importing the generated Client .p12 mTLS certificate on iOS.
My understanding is this is frequently caused by incompatible encryption methods between modern certificate generation tools (like OpenSSL 3.x and in this case SSLMate’s go-pkcs12 Modern) and iOS’s older security standards.
The relevant portion of code is below:
// Generate PKCS#12 (.p12) file
p12Data, err := pkcs12.Modern.Encode(clientKey, clientCert, []*x509.Certificate{caCert}, req.P12Password)
if err != nil {
return nil, fmt.Errorf("failed to generate PKCS#12: %w", err)
}
If this is changed to:
// Generate PKCS#12 (.p12) file
p12Data, err := pkcs12.Legacy.Encode(clientKey, clientCert, []*x509.Certificate{caCert}, req.P12Password)
if err != nil {
return nil, fmt.Errorf("failed to generate PKCS#12: %w", err)
}
The generated client certificates can be imported by iOS devices.
I have forked the repo and tested it (it works) but would not advocate this change. An option to select legacy (only when required) would be preferable. Unfortunately the changes to the database where certs and keys are stored and the UI to make Legacy selectable are beyond me.
44a80ab152
Co-Authored-By: gerthomas <34512947+gerthomas@users.noreply.github.com>
add a legacy_p12 boolean to CreateClientRequest (backend model and frontend type) to support generating PKCS#12 files with legacy encryption for iOS/older device compatibility. CertGenerator now selects pkcs12.Legacy when legacy_p12 is true (defaults to Modern otherwise). UI: add a checkbox to the client cert creation dialog and initialize form state to include legacy_p12.
Key middleware entries in generated and proxied Traefik configs by middleware name (so chain references by name work) instead of by ID. Join middleware names in resource queries and scan them (with fallback to ID when name is not available), add Name fields to middleware structs, and use the extracted base name when building final middleware references. Also update log messages to include both name and ID. In the UI, enforce and auto-sanitize middleware names to lowercase a-z0-9- and hyphens only.
Refine PluginCard UI: show 'Installed (Error)' when an installed plugin has an error, change the 'not_loaded/configured' state to use a secondary variant and label it 'Installed' (with Activity icon), and update the remove button from destructive to outline while applying destructive text/hover styles. These tweaks clarify installed states and make the removal action visually less aggressive while preserving disable/tooltip behavior.
Visual and structural refresh across the UI: adjust spacing and paddings, update theme tokens, and simplify several components for a cleaner look and interaction.
Highlights:
- App.tsx: increased main vertical padding (py-8).
- EmptyState: switched to muted translucent background and larger padding.
- Header: refined nav button styles (hover/opacity), added primary icon color, tighter spacing, replaced Button with native button, added active underline indicator and improved text styles.
- Dashboard: spacing tweaks (space-y changes), replaced Globe icon for TCP Routes with Network, updated stat descriptions and colors, moved New Middleware button inline, removed the old Quick Actions card grid and cleaned up tabs content spacing.
- StatCard: refactored layout (removed trend), added color prop with icon color mapping, updated typography and hover/border effects.
- ui/card: adjusted card border/shadow for dark mode and reduced CardTitle size.
- ui/table: tightened header/cell sizing and updated header styling to uppercase/tracking.
- globals.css: overhauled light/dark CSS color variables (hue/saturation/lightness values) and adjusted scrollbar thumb opacity.
These changes aim to unify the visual language, improve spacing and responsiveness, and simplify card/stat presentation for better clarity and interactivity.
Remove hardcoded plugin version in SecurityHub and prefer the plugin catalogue's recommended/latest version when available. Updated mtlsStore to import pluginApi, fetch the catalogue in checkPlugin, and set pluginStatus.version and recommended_version (fallbacks: installed -> recommended -> empty/default). Added MTLS_PLUGIN_MODULE constant and resilient error handling for catalogue fetch. Also added recommended_version to PluginCheckResponse type and updated UI snippets/badge to show installed or recommended version.
Introduce support for Traefik-native external middlewares referenced by resources.
- Database: add resource_external_middlewares table in migrations and ensure creation in post-migration updates.
- API: add handlers and routes to assign, remove and list external middlewares; include external_middlewares field in GetResources/GetResource responses (comma-separated name:priority:provider entries). Handlers validate resource status, use transactions, and log errors.
- Services: ConfigProxy now loads external middleware refs, merges them with internal middlewares sorted by priority when building resource config.
- UI: Resource detail component, API client, store and types updated to expose listing, assigning and removing external middlewares with UI controls and confirmation modal.
- Tests: add unit tests for assign/remove/list handlers and inclusion on GetResource.
This enables referencing middlewares defined outside MW-manager (e.g., Traefik dynamic config or plugins) and honors priority/provider metadata.