Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
82 changes: 82 additions & 0 deletions .github/workflows/check-pr.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
name: Vérification des pull requests (build, accessibilité et PDF)

# Mêmes étapes de construction que le déploiement, sans déploiement ni secret :
# le site et les PDF du portail (livre blanc, statuts, règlement intérieur, charte) sont validés
# avant fusion, et les PDF joints en artefact pour relecture.

on:
pull_request:
branches: ["main"]

concurrency:
group: "check-pr-${{ github.event.pull_request.number }}"
cancel-in-progress: true

permissions:
contents: read

jobs:
check:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
persist-credentials: false

- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
cache: pip

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt -r requirements-pdf.txt
sudo apt-get update
sudo apt-get install -y libpango-1.0-0 libpangoft2-1.0-0 poppler-utils

- name: Build documentation
run: mkdocs build --strict

# Accessibilité des pages HTML (WCAG 2 AA, moteur axe) : Chrome du runner, sans téléchargement
- name: Set up Node.js
uses: actions/setup-node@v4
with:
node-version: "22"

- name: Check accessibility (pa11y, axe)
env:
PUPPETEER_SKIP_DOWNLOAD: "true"
CHROME: /usr/bin/google-chrome
run: |
npm install --no-save --no-audit --no-fund pa11y@9
node scripts/check_a11y.js site

- name: Export PDF
run: python scripts/export_pdf.py

- name: Cache veraPDF
uses: actions/cache@v4
with:
path: ~/.cache/verapdf
key: verapdf-1.30.2

- name: Validate PDF/UA-1
run: bash scripts/check_pdf_ua.sh

# Polices embarquées : Inter pour le texte ; toute autre police signale un glyphe absent d'Inter
- name: List embedded fonts
run: |
for pdf in $(find site -name 'otspi-*.pdf' | sort); do
echo "== $pdf"
pdffonts "$pdf"
done

- name: Upload PDF
uses: actions/upload-artifact@v4
with:
name: portail-pdf
path: site/**/otspi-*.pdf
retention-days: 14
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -3,3 +3,4 @@ __pycache__/
*.py[cod]
.venv/
.DS_Store
node_modules/
10 changes: 5 additions & 5 deletions docs/adhesion/bulletin-adhesion.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Les demandes d'adhésion et dossiers complétés sont à transmettre à l'adress

---

## 1. Collèges et Conditions d'Adhésion
## 1. Collèges et conditions d'adhésion

Conformément aux Articles 5, 5 bis et 5 quater des Statuts :

Expand All @@ -34,10 +34,10 @@ Conformément aux Articles 5, 5 bis et 5 quater des Statuts :

---

## 2. Formulaire pour Personne Physique
## 2. Formulaire pour personne physique

```markdown
### Demande d'adhésion — Personne Physique
### Demande d'adhésion — personne physique

- **Nom légal** :
- **Prénom(s)** :
Expand Down Expand Up @@ -75,10 +75,10 @@ Signature :

---

## 3. Formulaire pour Personne Morale
## 3. Formulaire pour personne morale

```markdown
### Demande d'adhésion — Personne Morale
### Demande d'adhésion — personne morale

- **Raison sociale de l'organisation** :
- **Forme juridique** (ex. Association, Fondation, SA, SAS, Établissement Public) :
Expand Down
14 changes: 7 additions & 7 deletions docs/administratif/declaration-prefecture.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Guide des Démarches Administratives et Juridiques
# Guide des démarches administratives et juridiques

**Création et Immatriculation de l'Association « OTSPI » (Loi 1901)**
*« Open Trusted Service Provider Initiative »*
Expand All @@ -9,7 +9,7 @@ Ce document récapitule la procédure légale et administrative pour enregistrer

---

## Étape 1 : Rédaction et Signature des Documents Constitutifs
## Étape 1 : rédaction et signature des documents constitutifs

Avant de procéder à la déclaration, réunir les documents suivants paraphés et signés :
1. **Les Statuts** : [statuts-association.md](../statuts/statuts-association.md) complétés avec l'adresse du siège social dans la Métropole de Lyon, datés du jour de l'assemblée générale constitutive et signés par les dirigeants fondateurs (Président(e) et Trésorier(e)).
Expand All @@ -18,7 +18,7 @@ Avant de procéder à la déclaration, réunir les documents suivants paraphés

---

## Étape 2 : Déclaration en Préfecture (Télédéclaration e-création)
## Étape 2 : déclaration en préfecture (télédéclaration e-création)

La déclaration se réalise de manière dématérialisée sur le portail officiel de l'administration française :

Expand All @@ -34,15 +34,15 @@ La déclaration se réalise de manière dématérialisée sur le portail officie

---

## Étape 3 : Récépissé de Déclaration et Numéro RNA
## Étape 3 : récépissé de déclaration et numéro RNA

- Dans un délai généralement compris entre **24 heures et 5 jours ouvrés**, la Préfecture du Rhône / Métropole de Lyon valide le dossier.
- L'administration délivre un **Récépissé de Déclaration de Création**.
- Ce récépissé contient le **Numéro RNA** (Répertoire National des Associations, ex : `W691...`).

---

## Étape 4 : Publication au Journal Officiel (JOAFE)
## Étape 4 : publication au Journal officiel (JOAFE)

- La publication au **Journal Officiel des Associations et Fondations d'Entreprise (JOAFE)** est automatique et gratuite.
- La préfecture transmet directement l'avis de publication à la Direction de l'Information Légale et Administrative (DILA).
Expand All @@ -52,7 +52,7 @@ La déclaration se réalise de manière dématérialisée sur le portail officie

---

## Étape 5 : Obtention des Numéros SIREN et SIRET (INSEE)
## Étape 5 : obtention des numéros SIREN et SIRET (INSEE)

Pour ouvrir un compte bancaire associatif, souscrire aux polices de garantie financière et d'assurance responsabilité civile professionnelle, employer du personnel ou recevoir des financements et mécénats, l'association doit disposer d'un numéro SIRET.

Expand All @@ -66,7 +66,7 @@ Pour ouvrir un compte bancaire associatif, souscrire aux polices de garantie fin

---

## Étape 6 : Ouverture du Compte Bancaire et Fonds de Réserve
## Étape 6 : ouverture du compte bancaire et fonds de réserve

Une fois les identifiants officiels obtenus :
- Ouverture du compte courant d'exploitation auprès d'un établissement bancaire ;
Expand Down
93 changes: 93 additions & 0 deletions docs/assets/fonts/inter/OFL.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
Copyright 2016 The Inter Project Authors (https://github.com/rsms/inter) Inter-Italic[opsz,wght].ttf: Copyright 2016 The Inter Project Authors (https://github.com/rsms/inter)

This Font Software is licensed under the SIL Open Font License, Version 1.1.
This license is copied below, and is also available with a FAQ at:
http://scripts.sil.org/OFL


-----------------------------------------------------------
SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007
-----------------------------------------------------------

PREAMBLE
The goals of the Open Font License (OFL) are to stimulate worldwide
development of collaborative font projects, to support the font creation
efforts of academic and linguistic communities, and to provide a free and
open framework in which fonts may be shared and improved in partnership
with others.

The OFL allows the licensed fonts to be used, studied, modified and
redistributed freely as long as they are not sold by themselves. The
fonts, including any derivative works, can be bundled, embedded,
redistributed and/or sold with any software provided that any reserved
names are not used by derivative works. The fonts and derivatives,
however, cannot be released under any other type of license. The
requirement for fonts to remain under this license does not apply
to any document created using the fonts or their derivatives.

DEFINITIONS
"Font Software" refers to the set of files released by the Copyright
Holder(s) under this license and clearly marked as such. This may
include source files, build scripts and documentation.

"Reserved Font Name" refers to any names specified as such after the
copyright statement(s).

"Original Version" refers to the collection of Font Software components as
distributed by the Copyright Holder(s).

"Modified Version" refers to any derivative made by adding to, deleting,
or substituting -- in part or in whole -- any of the components of the
Original Version, by changing formats or by porting the Font Software to a
new environment.

"Author" refers to any designer, engineer, programmer, technical
writer or other person who contributed to the Font Software.

PERMISSION & CONDITIONS
Permission is hereby granted, free of charge, to any person obtaining
a copy of the Font Software, to use, study, copy, merge, embed, modify,
redistribute, and sell modified and unmodified copies of the Font
Software, subject to the following conditions:

1) Neither the Font Software nor any of its individual components,
in Original or Modified Versions, may be sold by itself.

2) Original or Modified Versions of the Font Software may be bundled,
redistributed and/or sold with any software, provided that each copy
contains the above copyright notice and this license. These can be
included either as stand-alone text files, human-readable headers or
in the appropriate machine-readable metadata fields within text or
binary files as long as those fields can be easily viewed by the user.

3) No Modified Version of the Font Software may use the Reserved Font
Name(s) unless explicit written permission is granted by the corresponding
Copyright Holder. This restriction only applies to the primary font name as
presented to the users.

4) The name(s) of the Copyright Holder(s) or the Author(s) of the Font
Software shall not be used to promote, endorse or advertise any
Modified Version, except to acknowledge the contribution(s) of the
Copyright Holder(s) and the Author(s) or with their explicit written
permission.

5) The Font Software, modified or unmodified, in part or in whole,
must be distributed entirely under this license, and must not be
distributed under any other license. The requirement for fonts to
remain under this license does not apply to any document created
using the Font Software.

TERMINATION
This license becomes null and void if any of the above conditions are
not met.

DISCLAIMER
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
OTHER DEALINGS IN THE FONT SOFTWARE.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
16 changes: 6 additions & 10 deletions docs/assets/logo-vertical-dark.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/assets/og/og-portail.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
18 changes: 9 additions & 9 deletions docs/cadrage/cp-cps-cadre.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Cadre Général des Politiques de Certification et Pratiques (CP/CPS)
# Cadre général des politiques de certification et pratiques (CP/CPS)
## Conforme à la RFC 3647, ETSI EN 319 401, ETSI EN 319 411-1 / 411-2 et WebTrust

**Association « Open Trusted Service Provider Initiative » (OTSPI)**
Expand All @@ -25,7 +25,7 @@ Le présent document définit les Politiques de Certification (*Certificate Poli

---

## 2. Répertoires de Publication et Référentiels
## 2. Répertoires de publication et référentiels

### 2.1. Répertoires publics
OTSPI maintient un répertoire accessible publiquement, de façon continue (24h/24, 7j/7), neutre et gratuite, contenant :
Expand All @@ -39,7 +39,7 @@ La disponibilité des services de publication de révocation (CRL/OCSP) fait l'o

---

## 3. Identification et Authentification (I&A)
## 3. Identification et authentification (I&A)

### 3.1. Enregistrement initial
- **Officiers d'Autorité et Gardiens de clés** : Identification civile formelle en présence physique ou par PVID qualifié, vérification du casier judiciaire, serment déontologique (Article 5 du Règlement Intérieur).
Expand All @@ -50,7 +50,7 @@ Tous les accès administratifs et d'émission requièrent des clés matérielles

---

## 4. Exigences Opérationnelles du Cycle de Vie des Certificats
## 4. Exigences opérationnelles du cycle de vie des certificats

### 4.1. Demande et émission de certificats
Toute demande de certificat suit un processus automatisé ou validé par un Officier d'Autorité selon le profil d'usage. L'émission est signée exclusivement au sein d'un module matériel de sécurité (HSM) qualifié.
Expand All @@ -62,7 +62,7 @@ Toute demande de certificat suit un processus automatisé ou validé par un Offi

---

## 5. Contrôles de Sécurité Physique, Environnementale et Procédurale
## 5. Contrôles de sécurité physique, environnementale et procédurale

### 5.1. Sécurité physique des sites d'hébergement
Les composants serveurs et modules HSM sont hébergés au sein de datacenters certifiés ISO/IEC 27001 et qualifiés SecNumCloud (ou équivalent européen souverain), situés exclusivement sur le territoire de l'Union Européenne :
Expand All @@ -75,7 +75,7 @@ Toute opération sur les HSM ou sur les clés racines (génération, sauvegarde,

---

## 6. Contrôles Techniques de Sécurité et Cycle de Vie des Clés
## 6. Contrôles techniques de sécurité et cycle de vie des clés

### 6.1. Modules matériels de sécurité (HSM)
- Les clés privées racines et intermédiaires sont générées et stockées exclusivement au sein de modules HSM certifiés **Common Criteria EAL 4+ (profil de protection EN 419 221-5)** ou **FIPS 140-2 / 140-3 Niveau 3**.
Expand All @@ -94,23 +94,23 @@ Conformément aux référentiels ETSI TS 119 312 et aux recommandations de l'ANS

---

## 7. Profils de Certificats, de CRL et d'Horodatage
## 7. Profils de certificats, de CRL et d'horodatage

1. **Profils X.509 v3** : Conformes aux normes IETF RFC 5280 et profils ETSI EN 319 412 (parties 1 à 5).
2. **Profils d'horodatage qualifié** : Conformes à la RFC 3161 et ETSI EN 319 421 / 422.
3. **Profils CRL v2** : Émission périodique (au moins toutes les 24 heures pour les intermédiaires, et à chaque révocation immédiate) signée par l'autorité émettrice.

---

## 8. Audit de Conformité et Évaluation
## 8. Audit de conformité et évaluation

1. **Audits internes périodiques** : Réalisés sous la responsabilité de l'Auditeur Interne indépendant nommé en coordination avec le CPC.
2. **Audits externes d'accréditation** : Conduits au moins tous les deux (2) ans (avec audits de surveillance annuels) par un organisme d'évaluation de la conformité (*Conformity Assessment Body - CAB*) accrédité selon la norme ISO/IEC 17065 et ETSI EN 319 403 / 403-1.
3. **Publication des rapports d'audit** : Les attestations d'audit (*Audit Attestations*) sont publiées dans le cadre de la redevabilité publique intégrale.

---

## 9. Dispositions Légales, Responsabilités et Droit Applicable
## 9. Dispositions légales, responsabilités et droit applicable

1. **Inaliénabilité des clés et séquestre** : Les clés privées sont insaisissables et sous séquestre technique exclusif (Article 8 ter des Statuts).
2. **Garanties financières et RC Pro** : Couverture par le fonds de réserve opérationnelle (Article 12 bis des Statuts) et police d'assurance responsabilité civile professionnelle souscrite par l'association.
Expand Down
Loading
Loading