Omahub
← All plugins
G

Certificate Wi-Fi

by grynov

Universal 802.1X EAP-TLS certificate Wi-Fi manager with automatic PKCS#12 extraction, validity monitoring, and instant setup.

Security review

Potentially dangerous behavior detected · 6 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
6a94055
Scanned
1 month ago
  • high destructive_filesystem tests/test_cert_helper.sh:198

    Low-level disk manipulation or write command.

    dd if=/dev/zero of="$TEST_DISCOVER_DIR/huge.p12" bs=1M count=11 2>/dev/null
  • high destructive_filesystem tests/test_cert_helper.sh:258

    Low-level disk manipulation or write command.

    dd if=/dev/zero of="$OVERSIZED_P12" bs=1M count=12 2>/dev/null
  • high destructive_filesystem backend/cert-helper.sh:41

    Low-level disk manipulation or write command.

    shred sensitive decrypted private keys and staged bundles before directory removal
  • high destructive_filesystem backend/cert-helper.sh:42

    Low-level disk manipulation or write command.

    shred -u {} + 2>/dev/null || true
  • Docs sudo README.md:36

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed jq openssl networkmanager
  • Docs sudo README.md:84

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /var/lib/iwd/"<SSID>".8021x

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6a94055
Reviewed
1 month ago

The plugin is a legitimate 802.1X certificate Wi-Fi manager with a well-structured backend that includes security hardening (secure temp dirs, file validation, path traversal protection, and permission checks). The deterministic scan flagged `shred` and `dd` as destructive, but these are used for secure cleanup and test fixtures respectively, not for malicious purposes. The sudo commands in the README are documentation for installing dependencies and removing iwd profiles, not part of the plugin's runtime behavior.

  • The backend script executes system commands (nmcli, iwctl, openssl) and handles private keys, so a human should verify the full script for any unintended side effects.
  • The plugin stores decrypted private keys in ~/.local/share/cert-wifi with 700 permissions; ensure this is acceptable for the user's threat model.
  • The deterministic scan's high risk is based on false positives (shred for cleanup, dd in tests); actual runtime risk appears low.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/grynov/omarchy-cert-wifi --enable
System #system

Certificate Wi-Fi Manager for Omarchy

Universal Omarchy Quattro shell plugin for 802.1X EAP-TLS certificate-based Wi-Fi networks (including easyroam, eduroam, campus, and enterprise RADIUS networks).

<p align="center"> <img src="preview.png" alt="Certificate Wi-Fi Manager Interface" width="480"> </p>

Overview

Provides automated X.509 client certificate (.p12 / .pfx) extraction, cryptographic verification, leaf certificate isolation, server domain suffix matching, and certificate expiration monitoring.

Features

  • Universal 802.1X EAP-TLS: Connects to certificate-based wireless networks.
  • Auto-Discovery: Scans local download directories for .p12/.pfx bundles and detects nearby SSIDs.
  • Certificate Inspection: Extracts identity, validity range, and domain realm before installation.
  • Credential Protection: Passwords and private keys are piped via standard input to prevent process table exposure.
  • Cryptographic Verification: Verifies public and private key pairs prior to profile installation.
  • Leaf Isolation: Separates client leaf certificates (-clcerts) and CA chains (-cacerts) to avoid validation errors.
  • Server Validation: Supports CA bundle pinning and domain suffix matching for MitM protection.
  • Validity Monitoring: Bar widget tracks certificate expiration and indicates renewal status.
  • Backend Support: Compatible with NetworkManager (nmcli) and iwd.

Dependencies & Prerequisites

The plugin and backend helper script require the following system packages:

  • jq: Required for JSON serialization and parsing between the QML interface and backend engine.
  • openssl: Required for PKCS#12 (.p12/.pfx) decryption, leaf certificate isolation, and key verification.
  • networkmanager (nmcli) or iwd (iwctl): Required for Wi-Fi network configuration and connection management.
  • polkit / pkexec (optional): Required if managing iwd profiles without root privileges.

On Arch Linux / Omarchy:

sudo pacman -S --needed jq openssl networkmanager

Installation

Via Git / Plugin Manager

omarchy plugin add https://github.com/grynov/omarchy-cert-wifi.git --enable

Manual Installation (Development)

mkdir -p ~/.config/omarchy/plugins/io.github.grynov.cert-wifi
cp -r * ~/.config/omarchy/plugins/io.github.grynov.cert-wifi/
# Or create a symlink for live development:
# ln -s "$(pwd)" ~/.config/omarchy/plugins/io.github.grynov.cert-wifi

omarchy plugin enable io.github.grynov.cert-wifi right
omarchy-shell shell rescanPlugins

Uninstallation & Cleanup

Via Plugin Manager

omarchy plugin remove io.github.grynov.cert-wifi
omarchy-shell shell rescanPlugins

Cleanup Local / Dev Installation

To completely remove a manual development installation and clean up extracted certificates and network profiles:

# 1. Disable and delete the local plugin folder
omarchy plugin disable io.github.grynov.cert-wifi
rm -rf ~/.config/omarchy/plugins/io.github.grynov.cert-wifi
omarchy-shell shell rescanPlugins

# 2. (Optional) Remove stored certificate profiles, private keys, and metadata
rm -rf ~/.local/share/cert-wifi

# 3. (Optional) Remove configured Wi-Fi connection from your network backend
nmcli connection delete "<SSID>"
# For iwd:
# sudo rm -f /var/lib/iwd/"<SSID>".8021x

Backend Engine CLI

The backend engine can be run independently:

# Discover certificates and nearby SSIDs
./backend/cert-helper.sh discover

# Inspect certificate metadata
./backend/cert-helper.sh inspect --file /path/to/certificate.p12

# Install network profile
./backend/cert-helper.sh install --file cert.p12 --ssid "NetworkSSID" --domain "radius.example.com"

# List profiles and expiration dates
./backend/cert-helper.sh list

# Delete profile
./backend/cert-helper.sh delete --id NetworkSSID

License

MIT License. Copyright (c) 2026 Vladyslav Grynovetskyy.