╔══════════════════╗║ ▀▀█ ║║ ▄██████▄ ▀█ ║█████ █ █ █████ █████ █████ █████ █████ █████║ ██ ▀▀ ▄▄█ ║█ █ █ █ █ █ █ █ █ █ █ ║ ▀██████▄ ║█████ █ █████ █████ █████ █████ █ ████ ║ ██ ║ █ █ █ █ █ █ █ █ █ ║ ██▄ ▄██ ║█████ █ █████ █████ █ █ █ █████ █████║ ▀██████▀ ║S E R V I C E S ─────────────────────────────────────║ ║P U B L I C K E Y I N F R A S T R U C T U R E╚══════════════════╝
───────────────────────────────── SYSTEM INFO ──────────────────────────────────
───────────── SYSTEM INFO ──────────────
Root....:SYS SPACE SERVICES Root CA R1SHA-256.:B6:6C:A1:DF:A2:D6:59:4C:A6:4C:E7:CF:9B:EA:97:5116:83:33:66:AE:CF:11:C8:8B:D9:FA:B6:A2:04:79:47Arc.....:1.3.6.1.4.1.99999(policy OIDs hang off <arc>.<site>.n)Model...:one root, delegates, leaves; small issuing CAs per credential typeCRLs....:root 28 days, delegate 1 day, DER over HTTP, refetched hourlySites...:scanningSysOp...:certauth(every change is a clean rebuild and 126 assertions)
────────────────────────────────── MAIN MENU ───────────────────────────────────
This is a working certificate authority fabric modelled on the US DoD and Federal PKIs. One Certificate Policy, one offline root, delegate sites that may sign sites of their own, and leaf sites that issue end-entity certificates from small CAs split by credential type: identity, email, code signing, with a KRA escrowing encryption keys.
Relying parties authorize on the policy OID that survives RFC 5280 path validation, not on "the chain verified". Every certificate is linted against the profiles before release and revoked if it fails.
To trust it: download the root certificate, check its SHA-256 against the one above, and import it as a trusted authority. Every site's repository serves its CRLs over plain HTTP on purpose: revocation checking must not depend on TLS.
To browse a CA: pick a site above. The end-entity pages (enrollment, retrieval, CRL download) are open. Agent pages ask for an operator certificate, which ends at this proxy, so operators use the internal addresses.
Lab notice: the policy arc is an unregistered PEN and the Certificate Policy is a draft. Nothing here is an assertion about anything outside this fabric. Certificates issued here are worth exactly what a lab's are.
╔══════════════════════════════════════════════════════════════════════════════╗║(c) 2026 SYS SPACE SERVICES·certificate policy·readme║╚══════════════════════════════════════════════════════════════════════════════╝