pki.sgit.ai / documents / pki-registry

pki.sgit.ai: The Public Key Registry Has A Documented Failure To Learn From

TypeStrategy brief Versionv0.33.59 Date16 August 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

The brief that scoped this site. It takes one historical lesson — the global keyserver network was destroyed in 2019 by a certificate-flooding attack its own maintainer called unsalvageable, and the cause was a stated design goal (never delete), not a bug — and turns it into the registry's design. The three abused properties become rules. The tension with the corpus's own append-only pattern is resolved precisely rather than by instinct: append-only is safe when the writer owns what it writes. Revocation becomes a signed append rather than a deletion. Identity and mandate separate into independently revocable signed statements. And the build order puts a private registry before a public one: testable versus commitment.

Key concepts

Key ideas

On this site

Became the site: the failure page (build-order step 2), the four rules (step 3), identity and mandate (step 5, published as a concept ahead of the implementation), and the build order with its tensions and open questions carried across intact.

Read the document

📄 Original document · v0.33.59 · 16 August 2026 · rendered from the raw markdown (the source of truth)