Cryptographic Design & CP/CPS

Job ID: 39811267

Budget: $250 – $750 USD

Context

Milestone 1 is completed. The awardee receives all existing artifacts: code repositories, OpenAPI specifications, signed Docker images, deployment manifests, and operational runbooks for issuance and OCSP. The work continues from these inputs.

Scope of Milestone 2 (fixed)
1. Cryptographic Design (KMI)
• Key hierarchy and roles: Root → Issuing (intermediate CA) → OCSP.
• Mandatory parameters: algorithms and key sizes, validity periods, serial policy, required CKA_* attributes, rotation policy, labels/IDs nomenclature, AIA/CRL/OCSP publication controls and TTLs.
2. Certificate Profiles
• FES (.p12 packaging), FEA, OCSP signer, Issuing CA.
• KU/EKU, policy OIDs and CPS URI, Subject/SAN fields, basicConstraints and pathLen.
3. CP/CPS Documents
• CP — Certificate Policy (REV A) and CPS — Certification Practice Statement (REV A) compliant with RFC 3647 and RFC 5280, traceable to the cryptographic design and profiles.
4. Operational Runbooks
• Key Ceremony: step-by-step Root → Issuing → OCSP procedure, PKCS#11/OpenSSL commands, inputs/outputs, evidence control, CRL/OCSP publication.
• Configuration templates in JSON/YAML for profiles and parameters.
5. Integration with Existing Code
• Update Admin API OpenAPI to include policy fields (policyOID, CPS URI, AIA/CRL/OCSP bases) and labels/IDs association.
• Postman collection covering: Issuing registration, Issuing CSR export, signed chain upload, CRL publication, OCSP signer rotation.

Deliverables (auditable)
1. CRYPTO-DESIGN — REV A: KMI, parameters, key tables, rotation and AIA/CRL/OCSP publication policies.
2. Certificate Profiles — REV A: document + JSON/YAML files ready for consumption.
3. CP (REV A) and CPS (REV A): complete and consistent with the design and profiles.
4. Runbook “Key Ceremony” — REV A: executable procedure Root → Issuing → OCSP, PKCS#11/OpenSSL commands, CSR/chain handling, CRL publication.
5. OpenAPI update (pull request) and Postman collection (official export).
6. Validation Report: verified Root → Issuing → OCSP chain, RFC 5280 checks (extensions, validity, key usage), verified FES .p12 with PBES2-AES-256 and PBKDF2 ≥ 310,000, operational CRL/OCSP evidence, consolidated checksums/fingerprints.

Acceptance Criteria (outcome-based)
• Document consistency: CRYPTO-DESIGN, Profiles, CP, CPS without contradictions and with explicit cross-traceability.
• Profiles compliant with RFC 5280: KU/EKU/OID/CPS URI and AIA/CRL/OCSP defined exactly.
• FES .p12 verifiable on Windows 10/11 and macOS ≥ 13 with PBES2-AES-256 + PBKDF2 ≥ 310,000.
• OpenAPI + Postman functional for: Issuing registration, Issuing CSR export, signed chain upload, CRL publication, OCSP signer rotation.
• Evidence dossier delivered: chain, CRL and OCSP verified; fingerprints and checksums recorded.

Timeline & Payment
• Timeline: 5 calendar days from milestone kickoff.

Inputs Provided at Start
• Existing repositories, OpenAPI specs, images and deployment manifests, operational runbooks, and AIA/CRL/OCSP publication routes and variables.

Exclusions
• AdES (PAdES/XAdES/CAdES), RA/identity processes, Admin Console/UI, infrastructure/IaC provisioning, TSA, third-party certifications.

Governance, IP, and Confidentiality
• Work via pull requests in the Client’s GitHub organization with commit history and versioning.
• Full IP assignment over all code and documentation produced in this milestone.
• Mandatory NDA and adherence to internal security and change-control policies.

Required Profile
• Proven experience in PKI, RFC 3647/5280/6960, CP/CPS drafting, and certificate profile design.
• Operational command of PKCS#11 and OpenSSL, key ceremony design, and validation on Windows/macOS.
• Delivery strictly outcome-based, with exhaustive documentation aligned to standards.
Related categories: Cryptography OpenSSL