What pki.sgit.ai Is Missing: Mandate Is The Gap, And The Registry Is The Missing Half
Summary
A review of this site with seven recommended additions, written under a stated limitation the review itself treats as a finding: the site could not be read directly, because a fetch was refused by tooling that only permits URLs a search has already returned, and a search for the subdomain did not return the site. So the review works from the main site's index entry. It identifies the mandate as the largest gap, the bootstrap trap as the most linkable argument available, and the reframing that makes everything concrete — the shipped PKI has no revocation and no directory, which is precisely what a registry supplies.
Key concepts
- The four questions — whose key, what may it do, how does it get in, what happened when it was exercised
- Receipts as the third corner — recording identity and delegation without recording exercise leaves the most auditable event unrecorded
- Reuse the capability model — four tiers with the server holding only hashes, already implemented
- Trust roots stay open — a fractal structure requires each store to declare which roots it accepts
Key ideas
- A registry that records identity and not delegation is half a system.
- The registry is the missing half of a feature that already ships, which is a far stronger pitch than a general argument about key repositories.
- A second authorisation model in the same platform is a second thing to reason about, get wrong and document.
- The site being unreadable to an agent under a common tooling restriction is itself the finding — documentation that is excellent and unreachable.
On this site
Every recommendation in it is now either shipped on the site or published as an open question; the review's own text is captured here unchanged, including the recommendations that were already met before it could be read.