administering-linux
Manage Linux systems covering systemd services, process management, filesystems, networking, performance tuning, and troubleshooting. Use when deploying…
Configure TLS certificates and encryption for secure communications. Use when setting up HTTPS, securing service-to-service connections, implementing mutual TLS (mTLS), or debugging certificate issues.
$ npx -y skills add ancoleman/ai-design-components --skill implementing-tls --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/implementing-tlsContext preview
The summary Claude sees to decide when to auto-load this skill.
Configure TLS certificates and encryption for secure communications. Use when setting up HTTPS, securing service-to-service connections, implementing mutual TLS (mTLS), or debugging certificate issues.
name: implementing-tls description: Configure TLS certificates and encryption for secure communications. Use when setting up HTTPS, securing service-to-service connections, implementing mutual TLS (mTLS), or debugging certificate issues.
Implement Transport Layer Security (TLS) for encrypting network communications and authenticating services. Generate certificates, automate certificate lifecycle management with Let's Encrypt or internal CAs, configure TLS 1.3, implement mutual TLS for service authentication, and debug common certificate issues.
Trigger this skill when:
Use mkcert for trusted local certificates:
# Install mkcert brew install mkcert # macOS # sudo apt install mkcert # Linux # Install local CA mkcert -install # Generate certificate mkcert example.com localhost 127.0.0.1 # Creates: example.com+2.pem and example.com+2-key.pem
**Kubernetes with cert-manager:**
# Install cert-manager
helm install cert-manager jetstack/cert-manager \
--namespace cert-manager --create-namespace \
--set installCRDs=true
# Create Let's Encrypt issuer
kubectl apply -f - <<EOF
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-prod
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: admin@example.com
privateKeySecretRef:
name: letsencrypt-prod-key
solvers:
- http01:
ingress:
class: nginx
EOF**Traditional servers with Certbot:**
# Install certbot sudo apt install certbot # Obtain certificate sudo certbot certonly --standalone -d example.com -d www.example.com # Certificates saved to /etc/letsencrypt/live/example.com/
Generate internal CA with CFSSL:
# Install CFSSL brew install cfssl # macOS # Create CA cfssl genkey -initca ca-csr.json | cfssljson -bare ca # Generate server certificate cfssl gencert -ca=ca.pem -ca-key=ca-key.pem \ -config=ca-config.json -profile=server \ server-csr.json | cfssljson -bare server
See `examples/cfssl-ca/` for complete configuration files.
Enable TLS 1.3 and 1.2 only:
# Nginx ssl_protocols TLSv1.3 TLSv1.2; ssl_prefer_server_ciphers off; # Let client choose
Disable obsolete protocols: SSLv3, TLS 1.0, TLS 1.1.
**TLS 1.3 (5 cipher suites):**
TLS_AES_256_GCM_SHA384 # Recommended TLS_CHACHA20_POLY1305_SHA256 # Mobile-optimized TLS_AES_128_GCM_SHA256 # Performance
**TLS 1.2 fallback:**
ssl_ciphers 'ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-CHACHA20-POLY1305';
For detailed TLS 1.3 configuration, see `references/tls13-best-practices.md`.
Need TLS certificate?
│
├─ Public-facing (internet users)?
│ │
│ ├─ Single domain → Let's Encrypt with HTTP-01
│ │ Tools: certbot, cert-manager
│ │ Challenge: HTTP verification
│ │
│ └─ Multiple subdomains → Let's Encrypt with DNS-01
│ Tools: certbot with DNS plugin, cert-manager
│ Challenge: DNS TXT records
│ Supports: Wildcard certificates (*.example.com)
│
└─ Internal (corporate network)?
│
├─ Development → mkcert or self-signed
│ Tools: mkcert (trusted), openssl (basic)
│ No automation needed
│
└─ Production → Internal CA
│
├─ Small scale (<10 services) → CFSSL
│ Manual management acceptable
│
└─ Large scale (100+ services) → Vault PKI or cert-manager
Dynamic secrets, automatic rotationEnvironment? │ ├─ Kubernetes → cert-manager │ Native CRDs, Ingress integration │ Supports: Let's Encrypt, Vault, CA, self-signed │ ├─ Traditional servers (VMs) → Certbot (public) or CFSSL (internal) │ Plugins: nginx, apache, DNS providers │ Automated renewal via cron/systemd │ ├─ Microservices (any platform) → HashiCorp Vault PKI │ Dynamic secrets, short-lived certs │ API-driven, service mesh integration │ └─ Developer workstation → mkcert Trusted by browser automatically
**Use Standard TLS (server-only authentication) when:**
**Use Mutual TLS (both authenticate) when:**
See `references/mtls-guide.md` for mTLS implementation patterns.
**Quick generation with SANs:**
# Create OpenSSL config cat > san.cnf <<EOF [req] default_bits = 2048 prompt = no default_md = sha256 distinguished_name = dn req_extensions = v3_req [dn] CN = example.com [v3_req] subjectAltName = @alt_names [alt_names] DNS.1 = example.com DNS.2 = www.example.com DNS.3 = api.example.com IP.1 = 192.168.1.100 EOF # Generate key and certificate openssl req -x509 -newkey rsa:2048 -nodes \ -keyout
Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude
Repo: ancoleman/ai-design-components
Manage Linux systems covering systemd services, process management, filesystems, networking, performance tuning, and troubleshooting. Use when deploying…
Data pipelines, feature stores, and embedding generation for AI/ML systems. Use when building RAG pipelines, ML feature serving, or data transformations.…
Strategic guidance for designing modern data platforms, covering storage paradigms (data lake, warehouse, lakehouse), modeling approaches (dimensional,…
Design cloud network architectures with VPC patterns, subnet strategies, zero trust principles, and hybrid connectivity. Use when planning VPC topology,…
Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF,…
Assembles component outputs from AI Design Components skills into unified, production-ready component systems with validated token integration, proper import…