Key custody

Lab (ns1)

  • Config Ed25519: /opt/pfc/etc/sm-keys/config.ed25519.pem (0600). Rotate with rotate_config_key.py (re-sign + admin-history).

  • NPE: npe keygen --out /opt/pfc/etc/npe/lab then npe keygen --rotate --id .... Inbox id stays stable.

  • Bus PSK: /opt/pfc/etc/nats.env (PFC_NATS_KEY). Not git.

Production

Customer HSM / PKCS#11 for Ed25519 signatures and NPE seed. Private material never in git or world-readable files.

This is not a HIPAA/SOC 2/ISO certificate.