You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The aia folder changed to orca/output/aia but the documentation of the ceremony still mentions orca/aia
We don't mention in the ceremony doc that if you signed a CSR, you need to import it.
We could avoid the sudo in the archive check since we only check the checksums. This can be done by removing the --same-owner which makes the sudo necessary
We don't mention that the signed report needs to be saved/backed-up
Origin
Description
What could be even better in our product?
Following the first rotation of the online CA, here are some improvements :
nix run nixpks#vault-binprobably)aiafolder changed toorca/output/aiabut the documentation of the ceremony still mentionsorca/aiasudoin the archive check since we only check the checksums. This can be done by removing the--same-ownerwhich makes thesudonecessary