feat: port legacy TSYS-CA (admin-code PKI + tsys-bits) [#769][#783]

Excluded admin-code/*SECRETS.inc (real Nitrokey HSM PINs in the public
source repo) — SECRETS.inc.example template added in their place.
Rotation/history-purge ruling pending in #783. legacy-* trees exempt
from lint/pointer checks (historical verbatim code).

https://projects.knownelement.com/issues/769#note-4152
This commit is contained in:
2026-09-04 07:01:46 -05:00
parent 2eca50490d
commit af7c0f3478
29 changed files with 738 additions and 3 deletions
+11
View File
@@ -0,0 +1,11 @@
PKI CA Scripts
==============
**FAILURE TO FOLLOW SECURITY PROCEDURES CAN AND WILL RESULT IN CONSEQUENCES UP TO AND INCLUDING LEGAL ACTION. YOU ARE WARNED.**
These scripts facilitate the creation of a root certificate authority and one intermediate certificate.
These scripts have only been tested on the live-build Debian 9 environment.