Skip to content

Explanation

Understanding-oriented. Why this module looks the way it does, and which parts of that were forced by AWS or OpenPGP rather than chosen.

Concepts

Components

  • Roles and trust — the reader/certifier split, the rebind threat, MFA and federated sessions.
  • Key policies — the four principal classes, and why there is no Deny.

The decision record

These pages explain the design. The spec records how each decision was reached, what was rejected, and what is still open — including the one question that gates publishing a certificate at all.