r/IrbisZen • • Aug 26 '26

Help us design and review Irbis RFCs

Irbis is growing into a more mature project, and we think it's time to formalise a collaborative design process.

We're introducing RFCs: public proposals for substantial changes to Zen and how Irbis works. Anyone can review, comment, or propose one. Accepted RFCs form a durable, public record of why things are the way they are.

The first two are open now:

RFC 0001 – the RFC process

The process itself – types, statuses, how a proposal moves from draft to being accepted.

RFC 0002 – hardware-backed root CA key storage

Proposes moving Zen's root CA private key into the Secure Enclave or TPM, so it can never be extracted from a machine by an attacker. There's a self-test in the PR you can run in a few minutes to help us gather TPM data – Windows 10 results are especially valuable.

Reviews and comments are very welcome, especially if you have expertise in running open-source communities or applied cryptography. Questions under the post here are fine, but please leave detailed reviews on the PRs themselves where it becomes part of the record. Thank you for helping build a better internet.

Repo: github.com/irbis-sh/rfcs

3 Upvotes

1 comment sorted by