Ceremony Protocol

Root Signing Key Ceremony

Overview

Generate an offline root signing key on an air-gapped workstation, issue its self-signed certificate, and export the public half for distribution. Two roles perform and witness the ceremony, and each attests to what they saw.

Roles

Preparation Checklist

Prerequisites

Environment Verification

StepActionRole
1

Confirm and witness the air-gap before any key material exists.

CO

Key Generation

StepActionRole
2

Generate the root RSA-4096 keypair inside the air-gapped workstation.

CO
3

Build the certificate signing request for the root key.

CO
4

Issue the self-signed root certificate, valid for 20 years.

CO
5

Export the public key for distribution as a trust anchor.

CO

Witness Attestation

StepActionRole
6

Attest: "I witnessed the generation of the root signing key and the issuance of its certificate."

Wi
7

Attest: "I generated the root signing key, issued its self-signed certificate, and exported the public key."

CO

Expected Outputs

Transcript Fingerprint

At the end of the ceremony, the transcript fingerprint is displayed. Copy at least the first line (32 characters, shown in bold) into the field below before closing the terminal, while all participants are still present.

sha256

__ __ __ __ __ __ __ __

__ __ __ __ __ __ __ __

__ __ __ __ __ __ __ __

__ __ __ __ __ __ __ __

Signatures

By signing below, each participant attests to the accuracy and completeness of this ceremony.

Crypto Officer

Name: Alice Rivera

Signature
Date

Witness

Name: Bob Tanaka

Signature
Date