Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
69 changes: 69 additions & 0 deletions .github/workflows/check-pr.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
name: Vérification des pull requests (build et PDF)

# Mêmes étapes de construction que le déploiement, sans déploiement ni secret :
# le site et les PDF du livre blanc sont validés avant fusion, et les PDF joints en artefact pour relecture.

on:
pull_request:
branches: ["main"]

concurrency:
group: "check-pr-${{ github.event.pull_request.number }}"
cancel-in-progress: true

permissions:
contents: read

jobs:
check:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt -r requirements-pdf.txt
sudo apt-get update
sudo apt-get install -y libpango-1.0-0 libpangoft2-1.0-0 poppler-utils

- name: Build documentation
run: mkdocs build --strict

- name: Export whitepaper PDF
run: python scripts/export_pdf.py

- name: Cache veraPDF
uses: actions/cache@v4
with:
path: ~/.cache/verapdf
key: verapdf-1.30.2

- name: Validate PDF/UA-1
run: bash scripts/check_pdf_ua.sh

# Polices embarquées : Inter pour le texte ; toute autre police signale un glyphe absent d'Inter
- name: List embedded fonts
run: |
for pdf in site/livre-blanc/otspi-livre-blanc.pdf site/white-paper/otspi-white-paper.pdf; do
echo "== $pdf"
pdffonts "$pdf"
done

- name: Upload PDF
uses: actions/upload-artifact@v4
with:
name: livre-blanc-pdf
path: |
site/livre-blanc/otspi-livre-blanc.pdf
site/white-paper/otspi-white-paper.pdf
retention-days: 14
93 changes: 93 additions & 0 deletions docs/assets/fonts/inter/OFL.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
Copyright 2016 The Inter Project Authors (https://github.com/rsms/inter) Inter-Italic[opsz,wght].ttf: Copyright 2016 The Inter Project Authors (https://github.com/rsms/inter)

This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
http://scripts.sil.org/OFL


-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------

PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.

The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.

DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.

"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).

"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).

"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.

"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.

PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:

1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.

2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.

3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.

4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.

5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.

TERMINATION
This license becomes null and void if any of the above conditions are
not met.

DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
16 changes: 6 additions & 10 deletions docs/assets/logo-vertical-dark.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
14 changes: 10 additions & 4 deletions docs/livre-blanc/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ description: "Livre blanc de l'Open Trusted Service Provider Initiative : défai

<div class="wp-cover" markdown>

![OTSPI](../assets/logo-vertical.svg){ .wp-cover-logo }
![OTSPI](../assets/logo-vertical-dark.svg){ .wp-cover-logo }

<p class="wp-cover-kicker">Livre blanc</p>
<p class="wp-cover-title">Une infrastructure de services de confiance qualifiés d'utilité publique pour eIDAS 2.0</p>
Expand All @@ -25,6 +25,8 @@ description: "Livre blanc de l'Open Trusted Service Provider Initiative : défai
<p class="wp-download-note">La version PDF est balisée et validée au format PDF/UA-1 par l'outil de contrôle veraPDF ; cette validation automatique ne remplace pas un test avec un lecteur d'écran. La présente page (HTML) reste la version accessible de référence.</p>
</div>

<div class="wp-meta" markdown>

| | |
|---|---|
| **Émetteur** | Initiative « Open Trusted Service Provider Initiative » (OTSPI), association loi 1901 en cours de constitution |
Expand All @@ -34,6 +36,8 @@ description: "Livre blanc de l'Open Trusted Service Provider Initiative : défai
| **Licence** | Creative Commons Attribution 4.0 International (CC-BY-4.0) |
| **Contact** | [contact@otspi.org](mailto:contact@otspi.org) |

</div>

!!! note "Nature du document"
Le présent livre blanc expose une intention et une architecture cible. Il ne constitue ni une Politique d'Horodatage, ni une Déclaration des Pratiques de Certification (DPC), ni un engagement contractuel de service. Les références à des produits ou fournisseurs sont données à titre indicatif ; leur sélection définitive relèvera de procédures de mise en concurrence et de l'approbation du Comité des Politiques de Confiance (CPC).

Expand Down Expand Up @@ -376,20 +380,22 @@ Tout éditeur de solution de signature, commercial ou libre, peut s'appuyer sur
### 4.1. Hiérarchie de certification

<!-- diagram:hierarchy:start -->
<figure class="wp-diagram" markdown="0">
<figure class="wp-diagram" id="figure-1" markdown="0">
<svg class="wp-svg" viewBox="0 0 760 350" role="img" aria-labelledby="fr-h-t fr-h-d" xmlns="http://www.w3.org/2000/svg"><title id="fr-h-t">Hiérarchie de certification qualifiée d&#x27;OTSPI</title><desc id="fr-h-d">L&#x27;AC racine OTSPI, hors ligne et sous quorum, certifie l&#x27;AC intermédiaire d&#x27;horodatage, qui certifie les unités d&#x27;horodatage TSU-1 (site A) et TSU-2 (site B). Elle certifiera aussi de futures AC qualifiées de cachet, de signature et d&#x27;attestations.</desc><defs><marker id="arr-fr-h" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto"><path class="dg-arrow" d="M0 0 L10 5 L0 10 z"/></marker><marker id="arc-fr-h" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto"><path class="dg-arrow-cross" d="M0 0 L10 5 L0 10 z"/></marker></defs><path class="dg-edge" d="M380 74 C380 104 190 100 190 128" marker-end="url(#arr-fr-h)"/><path class="dg-edge dg-dash" d="M380 74 C380 104 570 100 570 128" marker-end="url(#arr-fr-h)"/><path class="dg-edge" d="M190 198 C190 228 100 224 100 256" marker-end="url(#arr-fr-h)"/><path class="dg-edge" d="M190 198 C190 228 290 224 290 256" marker-end="url(#arr-fr-h)"/><rect class="dg-root" x="230" y="10" width="300" height="64" rx="8"/><text class="dg-t" x="380.0" y="37" text-anchor="middle">AC racine OTSPI</text><text class="dg-s" x="380.0" y="58" text-anchor="middle">hors ligne · air-gap · quorum M-de-N</text><rect class="dg-box" x="60" y="130" width="260" height="68" rx="8"/><text class="dg-t" x="190.0" y="157" text-anchor="middle">AC intermédiaire Horodatage</text><text class="dg-s" x="190.0" y="178" text-anchor="middle">hors ligne ou en ligne restreinte</text><rect class="dg-future" x="440" y="130" width="260" height="68" rx="8"/><text class="dg-t" x="570.0" y="157" text-anchor="middle">AC qualifiées futures</text><text class="dg-s" x="570.0" y="178" text-anchor="middle">cachet · signature · attestations</text><rect class="dg-box" x="10" y="258" width="180" height="68" rx="8"/><text class="dg-t" x="100.0" y="285" text-anchor="middle">Unité d&#x27;horodatage TSU-1</text><text class="dg-s" x="100.0" y="306" text-anchor="middle">HSM en ligne — site A</text><rect class="dg-box" x="200" y="258" width="180" height="68" rx="8"/><text class="dg-t" x="290.0" y="285" text-anchor="middle">Unité d&#x27;horodatage TSU-2</text><text class="dg-s" x="290.0" y="306" text-anchor="middle">HSM en ligne — site B</text></svg>
<figcaption><span class="wp-fig-num">Figure 1</span> — Hiérarchie de certification qualifiée d&#x27;OTSPI</figcaption>
</figure>
<!-- diagram:hierarchy:end -->

- La **clé de l'AC Racine** n'est utilisée que lors de cérémonies planifiées : émission ou renouvellement des AC intermédiaires, émission des CRL de l'AC Racine.
- Chaque **unité d'horodatage (TSU)** dispose d'une clé propre, exclusivement réservée à la signature de jetons d'horodatage, générée et conservée dans un module cryptographique certifié.
- La période d'utilisation des clés TSU est inférieure à la durée de validité de leur certificat, conformément à l'ETSI EN 319 421, afin de garantir la vérifiabilité des jetons émis en fin de période.
- Les futures **AC qualifiées** de cachet, de signature et d'attestations (cf. § 6.1, phase 5) seront rattachées à cette même racine qualifiée, chacune sous une AC intermédiaire dédiée à un seul usage.
- Le futur service de certificats TLS (cf. § 2.4) repose sur **deux racines distinctes** de la racine qualifiée d'horodatage : une **racine WebTrust**, destinée aux magasins de confiance des systèmes d'exploitation et des navigateurs, et une **racine QWAC**, inscrite sur la liste de confiance européenne. Elles appliquent les mêmes principes de gouvernance (air-gap, quorum, cérémonies) et ne partagent aucune clé avec les AC d'horodatage, de cachet ou de signature.
- Le futur service de certificats TLS (cf. § 2.4) repose sur **deux racines distinctes** de la racine qualifiée d'horodatage ([figure 2](#figure-2)) : une **racine WebTrust**, destinée aux magasins de confiance des systèmes d'exploitation et des navigateurs, et une **racine QWAC**, inscrite sur la liste de confiance européenne. Elles appliquent les mêmes principes de gouvernance (air-gap, quorum, cérémonies) et ne partagent aucune clé avec les AC d'horodatage, de cachet ou de signature.

<!-- diagram:tls:start -->
<figure class="wp-diagram" markdown="0">
<figure class="wp-diagram" id="figure-2" markdown="0">
<svg class="wp-svg" viewBox="0 0 760 390" role="img" aria-labelledby="fr-t-t fr-t-d" xmlns="http://www.w3.org/2000/svg"><title id="fr-t-t">Hiérarchies de certification TLS d&#x27;OTSPI</title><desc id="fr-t-d">Deux racines distinctes : une racine WebTrust pour les magasins des navigateurs, une racine QWAC inscrite sur la liste de confiance européenne. La racine WebTrust certifie une sous-AC DV, qui émet des certificats serveur DV par ACME instantané. Une sous-AC hybride OV / QWAC, à clé unique, est certifiée par la racine WebTrust et, par signature croisée, par la racine QWAC ; elle émet des certificats OV / QWAC.</desc><defs><marker id="arr-fr-t" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto"><path class="dg-arrow" d="M0 0 L10 5 L0 10 z"/></marker><marker id="arc-fr-t" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto"><path class="dg-arrow-cross" d="M0 0 L10 5 L0 10 z"/></marker></defs><path class="dg-edge" d="M200 74 L200 140" marker-end="url(#arr-fr-t)"/><path class="dg-edge" d="M300 74 C300 108 500 104 500 138" marker-end="url(#arr-fr-t)"/><path class="dg-cross" d="M600 74 L600 138" marker-end="url(#arc-fr-t)"/><text class="dg-label" x="610" y="112">signature croisée</text><path class="dg-edge" d="M200 212 L200 288" marker-end="url(#arr-fr-t)"/><path class="dg-edge" d="M560 212 L560 288" marker-end="url(#arr-fr-t)"/><rect class="dg-root" x="60" y="10" width="280" height="64" rx="8"/><text class="dg-t" x="200.0" y="37" text-anchor="middle">Racine WebTrust</text><text class="dg-s" x="200.0" y="58" text-anchor="middle">magasins OS et navigateurs</text><rect class="dg-root" x="420" y="10" width="280" height="64" rx="8"/><text class="dg-t" x="560.0" y="37" text-anchor="middle">Racine QWAC</text><text class="dg-s" x="560.0" y="58" text-anchor="middle">liste de confiance européenne</text><rect class="dg-box" x="60" y="142" width="280" height="70" rx="8"/><text class="dg-t" x="200.0" y="169" text-anchor="middle">Sous-AC DV</text><text class="dg-s" x="200.0" y="190" text-anchor="middle">WebTrust uniquement · HSM standard</text><rect class="dg-box" x="420" y="142" width="280" height="70" rx="8"/><text class="dg-t" x="560.0" y="169" text-anchor="middle">Sous-AC hybride OV / QWAC</text><text class="dg-s" x="560.0" y="190" text-anchor="middle">une clé · deux certificats d&#x27;AC</text><rect class="dg-box" x="60" y="290" width="280" height="70" rx="8"/><text class="dg-t" x="200.0" y="317" text-anchor="middle">Certificats serveur DV</text><text class="dg-s" x="200.0" y="338" text-anchor="middle">usage Web · ACME instantané</text><rect class="dg-box" x="420" y="290" width="280" height="70" rx="8"/><text class="dg-t" x="560.0" y="317" text-anchor="middle">Certificats serveur OV / QWAC</text><text class="dg-s" x="560.0" y="338" text-anchor="middle">DSP2, eIDAS · ACME avec liaison de compte</text></svg>
<figcaption><span class="wp-fig-num">Figure 2</span> — Hiérarchies de certification TLS d&#x27;OTSPI</figcaption>
</figure>
<!-- diagram:tls:end -->

Expand Down
Loading
Loading