Repository navigation
docs(tsa): serve RFC 3161 timestamps and pick a policy OID - #97
Merged
Merged
Conversation
Add the time-stamp authority how-to, the operator policy OID walkthrough and the pki.tsa reference, list cryptosctl tsa certificates, and point the code-signing use case at the TSA. Refs CryptOS-PKI/cryptos-node#287 Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
Contributor
Author
|
Closing summary: adds the TSA how-to (serve-timestamps-tsa), the IANA PEN policy OID walkthrough (tsa-policy-oid), the pki.tsa reference, the cryptosctl tsa certificates entry, and updates the code-signing and overview use cases. Site build green; commands and outputs checked against the code. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Companion docs for the RFC 3161 time-stamp authority (task 6 of CryptOS-PKI/cryptos-node#287), which
CryptOS-PKI/cryptos-node#354 switches on from machine config.
using/serve-timestamps-tsa: switch the TSA on, with a maintenance-window calloutfor the reboot the switch needs. Then check status and the TSA certificate, ask for a timestamp
(Linux / macOS and PowerShell tabs), and verify it with
openssl ts -verify. It also covers what theTSA accepts, why it refuses (the clock gate, 403, 429), rotation and old tokens, and switching it off.
using/tsa-policy-oid: the operator policy OID walkthrough. Find or request an IANAPrivate Enterprise Number, assign an arc for the TSA policy, and check the OID. There is no default
policy, so every deployment sets its own.
reference/machine-config-tsa: everypki.tsafield with its default andlimits, and the
config applyerrors.reference/cryptosctl:tsa certificates.use-cases/code-signinganduse-cases/overview: they said CryptOS serves no timestamps. Theynow point at the new page.
The pages carry the "Arrives with" callout until the code is in a released image, as the SCEP page
does.
Refs CryptOS-PKI/cryptos-node#287
Merge order: merge this first, then CryptOS-PKI/cryptos-node#354, which closes the issue.
Verification
How this was verified
npm run build(the site build CI runs) passes with no broken links, andtask licenseis clean.Every command and expected output was checked against the code and a run of it:
openssl ts -reply -textaccuracy line for the default 1000 ms;openssl asn1parseoutput for the OID check;internal/config/tsa.go;cryptosctl tsa certificatescolumns.