The authoritative practices document is the
Certification Practice Statement
(OID 1.3.6.1.4.1.66538.2.0); this page is a summary.
A private PKI operated by Sunlit Bytes for Sunlit Workshop provenance: document signing, data-at-rest encryption, user and device identity, and SSH access. It is not a publicly trusted CA; relying parties install the Sunlit Bytes Root CA explicitly.
1.3.6.1.4.1.66538.2/crl/<ca>.crl (7-day validity, refreshed daily and on every
revocation) and OCSP at /ocsp (best-effort availability —
verifiers should prefer CRLs). Root-issued CAs are covered by an offline-signed
ARL refreshed at least annually.Questions: hello@sunlitbytes.com