feat: complete evidence restructuring worktree

This commit is contained in:
Codex
2026-08-26 11:39:02 +02:00
parent a54d4769dd
commit 38f02cfd08
56 changed files with 1981 additions and 1801 deletions
+18 -20
View File
@@ -1,13 +1,13 @@
# TLS per DWH REST
# TLS for DWH REST
La chiave DWH è accettabile solo sopra TLS verificato. Errori di autorizzazione o disponibilità
non autorizzano mai a disabilitare la verifica del certificato.
The DWH key may be used only over verified TLS. Authorization or availability errors never justify
disabling certificate verification.
## CA privata
## Private CA
Quando il DWH REST usa una CA aziendale, consegnare il certificato separatamente dalla chiave
API. La CA non è una credenziale, ma la sua integrità è un confine di sicurezza: deve restare
fuori da Git e non essere scrivibile da utenti non autorizzati.
When DWH REST uses an enterprise CA, deliver the certificate separately from the API key. The CA
is not a credential, but its integrity is part of the security boundary. Keep it out of Git and
make it unwritable by unauthorized users.
Esempio ACME Limited:
@@ -15,26 +15,24 @@ Esempio ACME Limited:
THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem
```
## Fingerprint fuori banda
## Out-of-band fingerprint
Calcolare il fingerprint del file ricevuto e confrontarlo attraverso un canale indipendente:
Calculate the fingerprint of the received file and compare it through an independent channel:
```bash
openssl x509 -noout -fingerprint -sha256 \
-in /absolute/protected/acme-ebikes-dwh-ca.pem
```
Il SAN del certificato deve includere il nome esatto usato dal binding, per esempio
`dwh.acme.example`.
The certificate SAN must include the exact name used by the binding, such as `dwh.acme.example`.
## Rinnovo
## Renewal
1. Preparare certificato e chain nuovi.
2. Confermare SAN e fingerprint fuori banda.
3. Distribuire la nuova CA ai client mantenendo temporaneamente la precedente.
4. Aggiornare il binding e confermare la connettività con TLS normale.
5. Installare il certificato server.
6. Ritirare il trust precedente dopo la finestra concordata.
1. Prepare the new certificate and chain.
2. Confirm the SAN and fingerprint out of band.
3. Distribute the new CA to clients while temporarily keeping the old one.
4. Update the binding and confirm connectivity with normal TLS.
5. Install the server certificate.
6. Remove the old trust after the agreed window.
Non usare `curl -k`, non disabilitare TLS e non incorporare certificati o fingerprint completi
nei documenti condivisi.
Do not use `curl -k`, disable TLS, or embed complete certificates or fingerprints in shared documents.