Ceremony Protocol
Generate an offline root signing key on an air-gapped workstation, issue its self-signed certificate, and export the public half for distribution. Two roles perform and witness the ceremony, and each attests to what they saw.
| Step | Action | Role |
|---|---|---|
| 1 | Confirm and witness the air-gap before any key material exists. |
CO |
| Step | Action | Role |
|---|---|---|
| 2 | Generate the root RSA-4096 keypair inside the air-gapped workstation. |
CO |
| 3 | Build the certificate signing request for the root key. |
CO |
| 4 | Issue the self-signed root certificate, valid for 20 years. |
CO |
| 5 | Export the public key for distribution as a trust anchor. |
CO |
| Step | Action | Role |
|---|---|---|
| 6 | Attest: "I witnessed the generation of the root signing key and the issuance of its certificate." |
Wi |
| 7 | Attest: "I generated the root signing key, issued its self-signed certificate, and exported the public key." |
CO |
At the end of the ceremony, the transcript fingerprint is displayed. Copy at least the first line (32 characters, shown in bold) into the field below before closing the terminal, while all participants are still present.
sha256
__ __ __ __ __ __ __ __
__ __ __ __ __ __ __ __
__ __ __ __ __ __ __ __
__ __ __ __ __ __ __ __
By signing below, each participant attests to the accuracy and completeness of this ceremony.
Crypto Officer
Name: Alice Rivera
Witness
Name: Bob Tanaka