nhi.sgit.ai / pki

PKI: the cryptographic half of the identity gap

This work now has its own site: pki.sgit.ai — the public key infrastructure for agents, designed in public from a documented failure. It was staged here first (this site is where the need is established); with the spin-out live, this page is the bridge. The NHI angle is unchanged: the shared-drives research found that no available system gives an agent its own identity, agent-level attribution, or encryption to a specific agent — per-agent keys in a registry are what would fill those empty rows.

What lives on pki.sgit.ai

The history

Why good public key repositories don't exist

The 2019 certificate-flooding attack that destroyed the global keyserver network: the three abused properties, why it was unrepairable by design, and what the replacement gave up.

Read on pki.sgit.ai →
The design

The four registry rules

Owner-only writes; revocation as a signed append; size-bounded records; every entry signed — published as the registry's stated design before the registry exists.

Read on pki.sgit.ai →
The concept

Identity vs. mandate

Who a key belongs to and what its holder is authorised to do, as separately revocable signed statements — the direct answer to "everything acts as you".

Read on pki.sgit.ai →
The build order

Private registry before public

A registry with one organisation's agents in it is testable; a global one is a commitment. The phases, the open questions, the stated tensions.

Read on pki.sgit.ai →

What stays on this site

How this connects to the rest of the site