╔══════════════════════════════════════════════════════════════════════════════╗
 SYS SPACE SERVICES PKI · Node 1 
╚══════════════════════════════════════════════════════════════════════════════╝
╔══════════════════════════════════════╗
 PKI · Node 1 
╚══════════════════════════════════════╝

SYS SPACE SERVICES public key infrastructure

───────────────────────────────── SYSTEM INFO ──────────────────────────────────
───────────── SYSTEM INFO ──────────────
Root....: SYS SPACE SERVICES Root CA R1
SHA-256.: B6:6C:A1:DF:A2:D6:59:4C:A6:4C:E7:CF:9B:EA:97:51
          16:83:33:66:AE:CF:11:C8:8B:D9:FA:B6:A2:04:79:47
Arc.....: 1.3.6.1.4.1.99999 (policy OIDs hang off <arc>.<site>.n)
Model...: one root, delegates, leaves; small issuing CAs per credential type
CRLs....: root 28 days, delegate 1 day, DER over HTTP, refetched hourly
Sites...: scanning
SysOp...: certauth (every change is a clean rebuild and 126 assertions)
────────────────────────────────── MAIN MENU ───────────────────────────────────
────────────── MAIN MENU ───────────────
Select:   (press a key)
──────────────────────────────────── SITES ─────────────────────────────────────
──────────────── SITES ─────────────────
SCANNING FABRIC 
─────────────────────────────────── BULLETIN ───────────────────────────────────
─────────────── BULLETIN ───────────────
This is a working certificate authority fabric modelled on the US DoD and Federal PKIs. One Certificate Policy, one offline root, delegate sites that may sign sites of their own, and leaf sites that issue end-entity certificates from small CAs split by credential type: identity, email, code signing, with a KRA escrowing encryption keys.

Relying parties authorize on the policy OID that survives RFC 5280 path validation, not on "the chain verified". Every certificate is linted against the profiles before release and revoked if it fails.

To trust it: download the root certificate, check its SHA-256 against the one above, and import it as a trusted authority. Every site's repository serves its CRLs over plain HTTP on purpose: revocation checking must not depend on TLS.

To browse a CA: pick a site above. The end-entity pages (enrollment, retrieval, CRL download) are open. Agent pages ask for an operator certificate, which ends at this proxy, so operators use the internal addresses.

Lab notice: the policy arc is an unregistered PEN and the Certificate Policy is a draft. Nothing here is an assertion about anything outside this fabric. Certificates issued here are worth exactly what a lab's are.
╔══════════════════════════════════════════════════════════════════════════════╗
 (c) 2026 SYS SPACE SERVICES · certificate policy · readme 
╚══════════════════════════════════════════════════════════════════════════════╝
────────────────────────────────────────
(c) 2026 SYS SPACE SERVICES
certificate policy · readme