import * as plugins from '../../plugins.js';
import { HttpProxy } from '../http-proxy/index.js';
import type { IRouteConfig } from './models/route-types.js';
import type { IAcmeOptions } from './models/interfaces.js';
import type { AcmeStateManager } from './acme-state-manager.js';
export interface ICertStatus {
    domain: string;
    status: 'valid' | 'pending' | 'expired' | 'error';
    expiryDate?: Date;
    issueDate?: Date;
    source: 'static' | 'acme' | 'custom';
    error?: string;
}
export interface ICertificateData {
    cert: string;
    key: string;
    ca?: string;
    expiryDate: Date;
    issueDate: Date;
    source?: 'static' | 'acme' | 'custom';
}
export declare class SmartCertManager {
    private routes;
    private certDir;
    private acmeOptions?;
    private initialState?;
    private certStore;
    private smartAcme;
    private httpProxy;
    private renewalTimer;
    private pendingChallenges;
    private challengeRoute;
    private certStatus;
    private globalAcmeDefaults;
    private updateRoutesCallback?;
    private challengeRouteActive;
    private isProvisioning;
    private acmeStateManager;
    private certProvisionFunction?;
    private certProvisionFallbackToAcme;
    constructor(routes: IRouteConfig[], certDir?: string, acmeOptions?: {
        email?: string;
        useProduction?: boolean;
        port?: number;
    }, initialState?: {
        challengeRouteActive?: boolean;
    });
    setHttpProxy(httpProxy: HttpProxy): void;
    /**
     * Set the ACME state manager
     */
    setAcmeStateManager(stateManager: AcmeStateManager): void;
    /**
     * Set global ACME defaults from top-level configuration
     */
    setGlobalAcmeDefaults(defaults: IAcmeOptions): void;
    /**
     * Set custom certificate provision function
     */
    setCertProvisionFunction(fn: (domain: string) => Promise<plugins.tsclass.network.ICert | 'http01'>): void;
    /**
     * Set whether to fallback to ACME if custom provision fails
     */
    setCertProvisionFallbackToAcme(fallback: boolean): void;
    /**
     * Set callback for updating routes (used for challenge routes)
     */
    setUpdateRoutesCallback(callback: (routes: IRouteConfig[]) => Promise<void>): void;
    /**
     * Initialize certificate manager and provision certificates for all routes
     */
    initialize(): Promise<void>;
    /**
     * Provision certificates for all routes that need them
     */
    provisionAllCertificates(): Promise<void>;
    /**
     * Provision certificate for a single route
     */
    provisionCertificate(route: IRouteConfig, allowConcurrent?: boolean): Promise<void>;
    /**
     * Provision ACME certificate
     */
    private provisionAcmeCertificate;
    /**
     * Provision static certificate
     */
    private provisionStaticCertificate;
    /**
     * Apply certificate to HttpProxy
     */
    private applyCertificate;
    /**
     * Extract domains from route configuration
     */
    private extractDomainsFromRoute;
    /**
     * Check if certificate is valid
     */
    private isCertificateValid;
    /**
     * Extract expiry date from a PEM certificate
     */
    private extractExpiryDate;
    /**
     * Add challenge route to SmartProxy
     *
     * This method adds a special route for ACME HTTP-01 challenges, which typically uses port 80.
     * Since we may already be listening on port 80 for regular routes, we need to be
     * careful about how we add this route to avoid binding conflicts.
     */
    private addChallengeRoute;
    /**
     * Remove challenge route from SmartProxy
     */
    private removeChallengeRoute;
    /**
     * Start renewal timer
     */
    private startRenewalTimer;
    /**
     * Check and renew certificates that are expiring
     */
    private checkAndRenewCertificates;
    /**
     * Update certificate status
     */
    private updateCertStatus;
    /**
     * Get certificate status for a route
     */
    getCertificateStatus(routeName: string): ICertStatus | undefined;
    /**
     * Force renewal of a certificate
     */
    renewCertificate(routeName: string): Promise<void>;
    /**
     * Setup challenge handler integration with SmartProxy routing
     */
    private setupChallengeHandler;
    /**
     * Stop certificate manager
     */
    stop(): Promise<void>;
    /**
     * Get ACME options (for recreating after route updates)
     */
    getAcmeOptions(): {
        email?: string;
        useProduction?: boolean;
        port?: number;
    } | undefined;
    /**
     * Get certificate manager state
     */
    getState(): {
        challengeRouteActive: boolean;
    };
}
