summaryrefslogtreecommitdiffstats
path: root/design/hs_pki_templates
diff options
context:
space:
mode:
Diffstat (limited to 'design/hs_pki_templates')
-rw-r--r--design/hs_pki_templates19
1 files changed, 19 insertions, 0 deletions
diff --git a/design/hs_pki_templates b/design/hs_pki_templates
new file mode 100644
index 0000000..3196fc6
--- /dev/null
+++ b/design/hs_pki_templates
@@ -0,0 +1,19 @@
+End user:
+ End user split in:
+ - soft stored certs
+ - obfuscated certs
+ - hardware secured certs
+
+ End user:
+ - Client certs (auth)
+ - E-mail certs (signing)
+ - Encryption
+
+ Device:
+ - TLS certs (encr/auth)
+ * server
+ * client
+ * server+client(?)
+
+ All above should be issued per application or generally applications should
+ leverage main user certificate