docs(09): create phase plan + resolve open questions

This commit is contained in:
2026-07-01 16:28:31 +02:00
parent 063666af3b
commit 812eb06d9b
6 changed files with 665 additions and 10 deletions
@@ -599,17 +599,17 @@ interface FileResponse {
---
## Open Questions
## Open Questions (RESOLVED)
1. **PFX cert-only creation (A2)**
- What we know: node-forge `toPkcs12Asn1(key, certs, password)` is documented
- What's unclear: whether `null` for key is accepted without throwing
- Recommendation: Implement and test early in Wave 0; if null throws, use `forge.pkcs12` lower-level API to create cert-only PKCS12 bag
- **RESOLVED:** Plan 06 implements: attempt `toPkcs12Asn1(null, certs, password)` first; if node-forge throws on null key, fall back to constructing a cert-only PKCS12 bag via lower-level `forge.pkcs12` certBag API. Resolution happens at execution time in Wave 5 Task 1 — no pre-execution blocker.
2. **Merge: does user also supply a private key file?**
- What we know: CONTEXT.md says "cert + optional private key" for PFX
- What's unclear: How the private key is provided (separate file? paste?)
- Recommendation: Planner should scope the merge endpoint to accept an optional private key as a third file field. If omitted, create cert-only PFX.
- **RESOLVED:** Private key support is explicitly deferred per CONTEXT.md `<deferred>` section (private key handling, key generation, PKCS#8 import). Initial implementation is cert-only PFX merge. No private key file field in Wave 5 merge endpoint. This is a conscious scope decision, not an oversight.
---