---
title: Charmhub | Deploy Kubernetes Dashboard using Charmhub - The Open Operator Collection
description: Deploy the latest version of Kubernetes Dashboard as a Kubernetes Operator
  on any cloud.
url: https://charmhub.io/kubernetes-dashboard/libraries/cert
---

# Kubernetes Dashboard

[Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

* [Canonical Kubernetes](https://charmhub.io/publisher/containers "View all packages from Canonical Kubernetes")

Platform:

stable 03bf0f6

```
juju deploy kubernetes-dashboard
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/kubernetes-dashboard/libraries/cert#drawer)

## charms.kubernetes\_dashboard.v1.cert

* [*Docstrings*Docstrings](https://charmhub.io/kubernetes-dashboard/libraries/cert)
  [*Code*Source code](https://charmhub.io/kubernetes-dashboard/libraries/cert/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.kubernetes_dashboard.v1.cert
    ```

    [Download cert.py](https://charmhub.io/kubernetes-dashboard/libraries/cert/download)
  + *Last updated* 13 Jan 2026
  + *Revision* Library version 1.0

#### Self-Signed Certificate Generator.

This charm library contains a class `SelfSignedCert` which can be used for generating self-signed
RSA certificates for use in TLS connections or otherwise. It does not currently provide much
configurability, apart from the FQDN the certificate should be associated with, a list of IP
addresses to be present in the Subject Alternative Name (SAN) field, validity and key length.

By default, generated certificates are valid for 365 years, and use a 2048-bit key size.

##### Getting Started

In order to use this library, you will need to fetch the library from Charmhub as normal, but you
will also need to add a dependency on the `cryptography` package to your charm:

```
cd some-charm
charmcraft fetch-lib charms.kubernetes_dashboard.v1.cert
echo <<-EOF >> requirements.txt
cryptography
EOF
```

Once complete, you can import the charm and use it like so (in the most simple form):

```
# ...
from charms.kubernetes_dashboard.v0.cert import SelfSignedCert
from ipaddress import IPv4Address

# Generate a certificate
self_signed_cert = SelfSigned(names=["test-service.dev"], ips=[IPv4Address("10.28.0.20")])

# Bytes representing the certificate in PEM format
certificate = self_signed_cert.cert

# Bytes representing the private key in PEM/PKCS8 format
key = self_signed_cert.key
```

You can also specify the validity period in days, and the required key size. The algorithm is
always RSA:

```
# ...
from charms.kubernetes_dashboard.v0.cert import SelfSignedCert
from ipaddress import IPv4Address

# Generate a certificate
self_signed_cert = SelfSigned(
    names=["some_app.my_namespace.svc.cluster.local"],
    ips=[IPv4Address("10.41.150.12"), IPv4Address("192.168.0.20")],
    key_size = 4096,
    validity = 3650
)
```

---

Index

* [class SelfSignedCert](https://charmhub.io/kubernetes-dashboard/libraries/cert#selfsignedcert)
* + [def \_\_init\_\_(
    self)](https://charmhub.io/kubernetes-dashboard/libraries/cert#selfsignedcert-__init__)
* + [def validate\_cert\_date(
    in\_crt)](https://charmhub.io/kubernetes-dashboard/libraries/cert#selfsignedcert-validate_cert_date)
* + [def sans\_from\_cert(
    in\_crt)](https://charmhub.io/kubernetes-dashboard/libraries/cert#selfsignedcert-sans_from_cert)

#### class SelfSignedCert

Description

A class used for generating self-signed RSA TLS certificates. None

Methods

SelfSignedCert.
\_\_init\_\_(

*self*
)

Initialise a new self-signed certificate.

Arguments

names

A list of FQDNs that should be placed in the Subject Alternative
Name field of the certificate. The first name in the list will be
used as the Common Name, Subject and Issuer field.

ips

A list of IPv4Address objects that should be present in the list
of Subject Alternative Names of the certificate.

key\_size

Size of the RSA Private Key to be generated. Defaults to 2048

validity

Period in days the certificate is valid for. Default is 365.

SelfSignedCert.
validate\_cert\_date(

in\_crt: bytes
)

SelfSignedCert.
sans\_from\_cert(

in\_crt: bytes
)
