Identities for entities did.bot
agent llm did
didbot plan tls-sources.md
5.1 kB
Markdown
at commit 18ba4fe0


id: tls-sources title: A certificate comes from somewhere other than this server's own ACME client status: open crates: [didbot-serve] dependsOn: [agent-accounts] exitCriterion: > A deployment serves agent hostnames over TLS from a certificate this server did not obtain, swaps it without a restart or a dropped connection, and says which source produced the one it is serving. #

tls-sources #

Obtaining a wildcard over ACME DNS-01 is the default and should stay the default: it needs no operator, renews itself, and works with the zone credential the deployment already holds. It is not the only place a certificate can come from, and some of the alternatives are what a deployment with an existing PKI actually has.

The deliverable is the seam first and the implementations second, the same way DnsProvider is the seam under dns-providers. A certificate source has to answer three things: produce a certificate now, say when it should next be replaced, and hand over a replacement without interrupting anything.

The sources #

What every source has to satisfy #

Provenance, because this certificate is load-bearing for identity #

Done #

Nothing closed yet.