# Install minica with Homebrew, apt, Nix

Small, simple certificate authority. Version 1.1.0 via Homebrew; verified 2026-07-29. Also installable with debian: sudo apt install minica.

## Install

```sh
sudo av install brew:minica
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install minica
```

  Evidence: local Homebrew formula metadata

### Linux

- Debian apt (92%):

```sh
sudo apt install minica
```

  Evidence: Debian stable package indexes: minica from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- Nix (92%):

```sh
nix profile install nixpkgs#minica
```

  Evidence: nixpkgs package indexes: pkgs/by-name/mi/minica/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

## Package facts

- **Package key:** brew:minica
- **Package manager:** Homebrew
- **Version:** 1.1.0
- **Source summary:** Small, simple certificate authority
- **Homepage:** <https://github.com/jsha/minica>
- **Repository:** <https://github.com/jsha/minica>
- **Last updated:** 2026-07-29T17:04:54+02:00
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- minica (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 1.1.0
## Project history and usage

minica is a small certificate-authority utility from the `jsha/minica` repository. Its README defines the intended trust model narrowly: it is for situations where the CA operator also operates each host that will use the generated certificate.

### Project history

The tool automatically creates a root key and certificate and then signs end-entity certificates for requested DNS names or IP addresses. It does not provide OCSP or CRL services, and the README positions it as appropriate for RPC systems or microservices rather than as a public CA or full PKI platform.

### How it is used

In practice, minica is used by developers and operators who need local or internal TLS certificates with more structure than a single ad hoc self-signed certificate. The Homebrew package installs a tiny Go-based CLI alternative to heavier internal-CA systems such as step-ca, Vault PKI, or a full ACME deployment when the operator controls both the CA and the hosts.

### Sources

- <https://github.com/jsha/minica>
- <https://pkg.go.dev/github.com/jsha/minica>


## Security Notes

narrow executable package without higher-risk signals.

- **Geiger risk:** green / low
- narrow executable package without higher-risk signals

## Other Package-Manager Records

- Debian apt - minica - 1.0-2+b16: normalized package name match | Debian stable package indexes: minica from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | super micro binary to issue new CAs | https://github.com/paultag/minica
- Nix - minica: normalized package name match | nixpkgs package indexes: pkgs/by-name/mi/minica/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
- Ubuntu apt - minica - 1.0-2build1: normalized package name match | Ubuntu 24.04 LTS package indexes: minica from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | super micro binary to issue new CAs | https://github.com/paultag/minica


## Combined YAML source

View the package source record on GitHub. [combined/minica.yml](https://github.com/mxcl/pkgdb/blob/main/combined/minica.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
