Skip to content

docs(tsa): serve RFC 3161 timestamps and pick a policy OID - #97

Merged
Bugs5382 merged 1 commit into
mainfrom
docs/287-tsa
Oct 6, 2026
Merged

Bugs5382 merged 1 commit into
mainfrom
docs/287-tsa

Conversation

@Bugs5382

@Bugs5382 Bugs5382 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

What and why

Companion docs for the RFC 3161 time-stamp authority (task 6 of CryptOS-PKI/cryptos-node#287), which
CryptOS-PKI/cryptos-node#354 switches on from machine config.

  • New how-to, using/serve-timestamps-tsa: switch the TSA on, with a maintenance-window callout
    for the reboot the switch needs. Then check status and the TSA certificate, ask for a timestamp
    (Linux / macOS and PowerShell tabs), and verify it with openssl ts -verify. It also covers what the
    TSA accepts, why it refuses (the clock gate, 403, 429), rotation and old tokens, and switching it off.
  • New how-to, using/tsa-policy-oid: the operator policy OID walkthrough. Find or request an IANA
    Private Enterprise Number, assign an arc for the TSA policy, and check the OID. There is no default
    policy, so every deployment sets its own.
  • New reference, reference/machine-config-tsa: every pki.tsa field with its default and
    limits, and the config apply errors.
  • reference/cryptosctl: tsa certificates.
  • use-cases/code-signing and use-cases/overview: they said CryptOS serves no timestamps. They
    now point at the new page.

The pages carry the "Arrives with" callout until the code is in a released image, as the SCEP page
does.

Refs CryptOS-PKI/cryptos-node#287

Merge order: merge this first, then CryptOS-PKI/cryptos-node#354, which closes the issue.

Verification

  • Lint clean
  • Tests pass
  • Build succeeds
  • Documentation updated (if behavior or API changed)

How this was verified

npm run build (the site build CI runs) passes with no broken links, and task license is clean.
Every command and expected output was checked against the code and a run of it:

  • the openssl ts -reply -text accuracy line for the default 1000 ms;
  • the openssl asn1parse output for the OID check;
  • the error messages, default port and field limits in internal/config/tsa.go;
  • the cryptosctl tsa certificates columns.

@Bugs5382 Bugs5382 self-assigned this Oct 6, 2026
Add the time-stamp authority how-to, the operator policy OID walkthrough
and the pki.tsa reference, list cryptosctl tsa certificates, and point
the code-signing use case at the TSA.

Refs CryptOS-PKI/cryptos-node#287

Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
@Bugs5382
Bugs5382 marked this pull request as ready for review October 6, 2026 20:14
@github-actions github-actions Bot added the documentation Documentation only (docs). label Oct 6, 2026
@Bugs5382

Bugs5382 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Closing summary: adds the TSA how-to (serve-timestamps-tsa), the IANA PEN policy OID walkthrough (tsa-policy-oid), the pki.tsa reference, the cryptosctl tsa certificates entry, and updates the code-signing and overview use cases. Site build green; commands and outputs checked against the code.

@Bugs5382
Bugs5382 merged commit fbfc297 into main Oct 6, 2026
16 checks passed
@Bugs5382
Bugs5382 deleted the docs/287-tsa branch October 6, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Documentation only (docs).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant