That is too much complexity for a single security-critical program.
That is too much complexity for a single security-critical program.
Most people do just one of a few operations, where they copy-paste the commands found online, as they do with windows registry, firefox about:config or ffmpeg, so it's no different than that.
You mean like this? https://iangetz.com/projects/ffmpeg-builder/
I'm a CLI guy, but `openssl` is insanely complex and I think it would benefit the ecosystem immensely if someone built a wrapper CLI that made it easier to complete the small handful of popular use cases that 90% of us have to go to Google to remember.
https://gist.github.com/tayvano/6e2d456a9897f55025e25035478a...
If you make a GUI out of this, it will be a pain in the ass... and ugly!
Luckily, there are many ffmpeg frontends, that select just a tiny subset of commands that are most often needed (like yours and many others), and the same things exist for openssl, eg:
I guarantee you, 10000%, that it will still be more usable than CLI is without having to google everything. FFMPEG is so complex that doing anything with it feels like talking in some ancient archaic code known only to the video tech wizards, and a GUI would absolutely make that better.
I think they call that VLC
FFmpeg is a practically an entire non-linear video editor in a CLI tool. That is indeed a lot of complexity, but the stakes are low -- if you screw up an FFmpeg command, you've lost some encoding time, not your entire password database. (I get the impression a lot of FFmpeg's functionality wouldn't serialize well, either, but I'm far from an expert on that.)
Nobody on Earth ever has or ever will like the Windows registry.
No comment on Firefox.
Looking at this x509 page, a lot of these options kind of seem like "required complexity" to me. There's a few things that aren't really needed (like the string conversion stuff) and a few things that could be condensed in one option (the "Print [..]" options can be one "print [list-of-fields]"), but those are relatively minor things.
The thing is, SSL/TLS is kinda complicated, but that's not really OpenSSL's fault.
If you want a tool that "just generates certificates" then it's easy, but if you want an advanced management tool that can do all sorts of things then you will end up with something complex because TLS is complex with a lot of different parts.
And yeah, the openssl tool could be designed a lot better, but much of this is a matter of UX and managing complexity, not so much reducing it.