PKI Foundation Hardening and Regulated Operations Roadmap

This project tracks the hardening and completion of the PKI foundation in the pki module.

Scope

  • bootstrap and SPI wiring without implementation-specific dependencies
  • X.509 issuance and status infrastructure built on BC where JDK support is insufficient
  • profile-driven issuance for regulated environments
  • approval workflows, including multi-level and threshold approval
  • remote signing and delegated signing boundaries
  • ACME-ready architecture
  • audit, evidence, and operational consistency improvements
  • targeted refactoring of correctness and maintainability hotspots

Goal

Build a professional PKI foundation suitable for strongly regulated environments, with deterministic behavior, explicit governance, auditable workflows, and clean separation between PKI orchestration and cryptographic execution.

15
Backlog
#6 opened 2026-03-24 17:59:39 +01:00 by galambos
#9 opened 2026-03-24 18:02:22 +01:00 by galambos
#12 opened 2026-03-24 18:04:35 +01:00 by galambos
0
Ready
0
In Progress
0
Review
0
Done