Your wallet
Your identity is a root, and the root lives in your wallet, never on this node. The node holds a leaf: a certificate your root issues to this host, for one address, until one date (HDTP §9, §14.1). The node makes the request, the wallet signs it, the node installs the answer:
hdtp-gateway account csr -slug me > me.csr # the request: this host's key and addresshdtp id issue --vault me.hdtp-vault.json --csr me.csr --chain-out chain.pemhdtp-gateway account install-leaf -slug me -chain chain.pemThe wallet a self-hoster uses is the hdtp CLI from hdtp-identity. hdtp id create makes the root
once, in a vault file under a passphrase; hdtp id issue shows what a request names and asks
before it signs. account csr prints only the request on its standard output (what it is for goes
to standard error), and install-leaf takes the two certificates --chain-out writes, leaf then
root. account csr -slug me -purpose renew asks for the next leaf before this one runs out, and
-purpose move for a leaf at a new address.
The root never comes to this node, and nothing here can make one: losing the vault and its passphrase is losing that identity.
A web wallet, from the portal. Once an identity has its first leaf, Identity → Sign with my
web wallet asks a web wallet (HDTP_WALLET_URL, https://ceremony.hdtp.io by default) for the
next one: a renewal, or a move when the address changes. The page shows what it will ask and
changes nothing until you continue; a request already waiting is replaced only if you confirm it.
The wallet sends its answer back to this node’s /wallet/return in the same browser, and the
portal installs it with your session. This is the node’s side of it. The wallet’s /sign page is
BatonDeck’s and is not live yet, and how browsers treat a public page sending you back to
http://localhost has not been measured, so until both are, use the hdtp CLI.
After a move. When an install moves the identity to a new address, both the CLI and the portal
say so, and say to run hdtp-gateway account announce -slug me until no contact is waiting: the
previous certificate stays valid until its own date for contacts not yet told. When the identity
came from another host, that is also when to delete it there. When this node itself moved to a new
address, there is nothing to delete: the previous certificate goes on answering here until it
expires.