ESTABLISH IDENTITY
Your hierarchy.
Your trust domain.
Issue certificates for services and clients you control. Separate root and issuer keys. Keep subscriber private keys local.
ML-DSA / CLASSICALPOST-QUANTUM CERTIFICATE INFRASTRUCTURE
FIELD NOTES / 001
The algorithms are moving.
Build the authority to move with
them.
qarc brings post-quantum signatures, explicit issuance policy, and inspectable evidence to private certificate infrastructure.
Inside the systemIN DEVELOPMENT · PRIVATE-PKI LAB
01 / THE SYSTEM
IDENTITY → POLICY → EVIDENCENot just a new signature algorithm. A deliberate chain from authority to identity—with controls you can examine.
ESTABLISH IDENTITY
Issue certificates for services and clients you control. Separate root and issuer keys. Keep subscriber private keys local.
ML-DSA / CLASSICALCONSTRAIN ISSUANCE
Declare client capabilities, pin acceptable roots, and constrain issuance with independently approved, signed policy catalogs.
EXPLICIT ADMISSIONRETAIN THE EVIDENCE
Trace certificate inventory, signing attempts, hash-linked audit records, and revocation status. A success message is not the whole story.
VERIFIABLE OPERATIONS02 / TRUST BOUNDARIES
NO BORROWED ASSURANCENo wall of badges. Here is the operating boundary, in plain language.
See the developer workflowPrivate certificates are for relying parties you control. qarc does not currently offer publicly trusted TLS issuance.
Distinct root and issuer keys establish separation. Custody, recovery, and access governance remain essential operational responsibilities.
Native cryptographic and independent interoperability tests inform development. HSM qualification and independent security review remain separate requirements.
PRODUCTION ISSUANCE DISABLED Admission work is still in progress.
03 / FOR BUILDERS
LOCAL KEYS. VERIFIED OUTPUT.The enrollment client submits a signed CSR, persists a retry reference, and verifies the returned certificate against your pinned hierarchy before writing output.
npm run enroll -- config.json service.pem
Requires the qarc source checkout, trusted configuration, an authorized credential, and an enabled isolated lab authority.
TWO ENTRIES. DISTINCT AUTHORITY.