Sort
PKI Foundation Hardening and Regulated Operations Roadmap
This project tracks the hardening and completion of the PKI foundation in the pki module.
Scope
- bootstrap and SPI wiring without implementation-specific dependencies
- X.509 issuance and status infrastructure built on BC where JDK support is insufficient
- profile-driven issuance for regulated environments
- approval workflows, including multi-level and threshold approval
- remote signing and delegated signing boundaries
- ACME-ready architecture
- audit, evidence, and operational consistency improvements
- targeted refactoring of correctness and maintainability hotspots
Goal
Build a professional PKI foundation suitable for strongly regulated environments, with deterministic behavior, explicit governance, auditable workflows, and clean separation between PKI orchestration and cryptographic execution.