summaryrefslogtreecommitdiffstats
path: root/design/hs_pki_policy
diff options
context:
space:
mode:
authord3llf <d3llf@hackerspace.pl>2017-02-05 12:53:47 +0100
committerd3llf <d3llf@hackerspace.pl>2017-02-05 12:53:47 +0100
commitf5c69eaf0b7359d0ce9be655d9fdce9212b57352 (patch)
treef474efad427c9aae663514d3558de02d6b693184 /design/hs_pki_policy
downloadhs_pki-f5c69eaf0b7359d0ce9be655d9fdce9212b57352.tar.gz
hs_pki-f5c69eaf0b7359d0ce9be655d9fdce9212b57352.tar.bz2
hs_pki-f5c69eaf0b7359d0ce9be655d9fdce9212b57352.tar.xz
hs_pki-f5c69eaf0b7359d0ce9be655d9fdce9212b57352.zip
Init commit: stub README; RFI for hs_pki_uc needed
Diffstat (limited to 'design/hs_pki_policy')
-rw-r--r--design/hs_pki_policy12
1 files changed, 12 insertions, 0 deletions
diff --git a/design/hs_pki_policy b/design/hs_pki_policy
new file mode 100644
index 0000000..b90e145
--- /dev/null
+++ b/design/hs_pki_policy
@@ -0,0 +1,12 @@
+Root CA cert valid for 6y
+Root CA CRL valid for 14m
+ * need ceremony at least once per y to renew CRL
+
+KC certificates valid for 8m (verify calculation of influence on possible new CA)
+
+CA certs valid for 1y
+ Limited certificate depth to 1 (so it can't issue CA)
+
+CA CRL valid for 1d (or even less)
+
+End user / device certificates valid for 3m