GUIDE · PKI
Files in and out of an offline root CA, without a USB stick
An offline root CA is switched on a few times a year to sign a subordinate CA certificate or a new CRL. Everything around it is scripted, witnessed and logged, except the USB stick that carries the request in and the certificate out: the one piece of hardware that crosses the air gap in both directions.
Written by Taha Bayar, who builds Kionel.
What moves, and how big it is
| File | Direction | Typical size | Route that fits |
|---|---|---|---|
| Subordinate CA request (CSR) | in | 1–2 KB | A one-way serial cable into the CA, or a camera on the CA machine |
| Signed subordinate CA certificate | out | 1–3 KB | Screen to a phone or laptop camera, or a printed page |
| CRL | out | from under 1 KB | Screen, printed page or serial cable |
| Ceremony log or transcript | out | tens of KB | Screen or serial cable |
At these sizes one or two codes carry the file: the transfer takes seconds. Printed pages double as the paper copy many ceremony procedures keep anyway.
Direction matters
- Out of the CA needs only a screen on the CA machine: it shows the file as encrypted codes and a device outside reads them. Nothing touches the CA.
- Into the CA needs either a camera on the CA machine or a serial cable wired one way into it: transmit and ground from the outside PC to the CA's receive pin, and nothing back. A CSR then goes in and nothing can come out on that cable.
Evidence for the ceremony record
With a business licence, each file carries a dispatch record signed by the sending device (the file's SHA-256, size, time, the ceremony reference and the operator's declared name) and a delivery receipt signed by the receiving device. A reviewer can check later that the certificate that left the CA is byte for byte the one that was installed, with the free, Apache-2.0 verifier. A receipt can also carry an RFC 3161 timestamp once the receiving device is online.
What it does not replace
- The ceremony itself. Witnesses, scripts, HSM quorum and video stay as they are; Kionel's records add a file-level trail to them.
- The HSM. Kionel's own signing keys are browser keys the device cannot export, not HSM keys. They sign the transfer records, never your CA's certificates.
- A browser on the CA machine. It needs Chrome, Edge or Firefox recent enough (serial needs Chrome or Edge); the offline package is one HTML file with a published SHA-256 you can check before it goes in.