Skip to content

Commit

Permalink
Script updating gh-pages from 435775e. [ci skip]
Browse files Browse the repository at this point in the history
  • Loading branch information
ID Bot committed Oct 10, 2024
1 parent 06a8661 commit 0f36bee
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 4 deletions.
2 changes: 1 addition & 1 deletion rpki/draft-dekater-scion-pki.html
Original file line number Diff line number Diff line change
Expand Up @@ -1646,7 +1646,7 @@ <h4 id="name-trust-hierarchy">
<h4 id="name-control-plane-root-certific">
<a href="#section-2.1.2" class="section-number selfRef">2.1.2. </a><a href="#name-control-plane-root-certific" class="section-name selfRef">Control Plane Root Certificate</a>
</h4>
<p id="section-2.1.2-1">The private key of the Control Plane root is used to sign Control Plane CA certificates. Consequently, the public key of the Control Plane Root certificate is used to verify Control Plane CA certificates, i.e. root certificates determine which ASes act as a CA in an ISD.<a href="#section-2.1.2-1" class="pilcrow"></a></p>
<p id="section-2.1.2-1">The private key of the Control Plane root certificate is used to sign Control Plane CA certificates. Consequently, the public key of the Control Plane Root certificate is used to verify Control Plane CA certificates, i.e. root certificates determine which ASes act as a CA in an ISD.<a href="#section-2.1.2-1" class="pilcrow"></a></p>
<p id="section-2.1.2-2">In X.509 terms, Control Plane root certificates are <em>self-signed</em> CA certificates. That is, issuer and subject of the certificate are the same entity, and the public key in the root certificate can be used to verify the root certificate's signature. The public key of the Control Plane root and proof of ownership of the private key are embedded in the TRC of an ISD, via the self-signed Control Plane root certificate. This facilitates the bootstrapping of trust within an ISD, and marks the Control Plane root certificates as the starting point of an ISD's certificate verification path.<a href="#section-2.1.2-2" class="pilcrow"></a></p>
<p id="section-2.1.2-3">The <span class="bcp14">RECOMMENDED</span> <strong>maximum validity period</strong> of a Control Plane root certificate is 1 year.<a href="#section-2.1.2-3" class="pilcrow"></a></p>
<p id="section-2.1.2-4"><strong>Note</strong>: The TRC of each ISD contains a trusted set of Control Plane root certificates, and this set builds the root of each ISD's verification path. For more information on the selection of this trusted set of root certificates, see <a href="#trc-specification" class="auto internal xref">Section 3</a>.<a href="#section-2.1.2-4" class="pilcrow"></a></p>
Expand Down
6 changes: 3 additions & 3 deletions rpki/draft-dekater-scion-pki.txt
Original file line number Diff line number Diff line change
Expand Up @@ -591,9 +591,9 @@ Table of Contents

2.1.2. Control Plane Root Certificate

The private key of the Control Plane root is used to sign Control
Plane CA certificates. Consequently, the public key of the Control
Plane Root certificate is used to verify Control Plane CA
The private key of the Control Plane root certificate is used to sign
Control Plane CA certificates. Consequently, the public key of the
Control Plane Root certificate is used to verify Control Plane CA
certificates, i.e. root certificates determine which ASes act as a CA
in an ISD.

Expand Down

0 comments on commit 0f36bee

Please sign in to comment.