Establish scoped KeyCape factor custody and verified automatic renewal
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
fd34ac98f0
commit
74b4f7f1bc
1 changed files with 10 additions and 7 deletions
|
|
@ -33,17 +33,18 @@ Validation: `go test ./...` and `git diff --check` passed on 2026-09-13. See doc
|
|||
|
||||
```task
|
||||
id: KEY-WP-0035-T02
|
||||
status: wait
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "b066a273-f91c-50ee-b497-a39eace03b3a"
|
||||
```
|
||||
|
||||
Live factor-read credentials return HTTP 401. The owner route
|
||||
net-kingdom-privacyidea-admin-token is non-resolvable pending railiance-platform's
|
||||
approved custody/renewal contract (NK-WP-0033). Native credential handoff required;
|
||||
no secrets in work records. Do not enable the policy before lookup is verified.
|
||||
Prepare exact byte-preserving client migration after the provider contract is
|
||||
available; deploy digest-pinned source and run no-factor/enrolled/error checks.
|
||||
Factor lookup restored on 2026-09-13 through the new dedicated service lane
|
||||
RPF-WP-0040 / CCR-2026-0023. Native ESO delivery, scoped provider user lookup,
|
||||
renewal and mounted replacement passed. KeyCape now uses adminTokenFile; other
|
||||
configuration and current MFA policy were preserved. Historical NK-WP-0033
|
||||
resolver lanes remain separate. The remaining T02 work is the exact scoped
|
||||
client migration and no-factor/enrolled/error/step-up acceptance before enabling
|
||||
optional policy. See railiance-platform/docs/evidence/2026-09-13-keycape-factor-custody.md.
|
||||
|
||||
## Verify optional enrollment and account management access
|
||||
|
||||
|
|
@ -73,3 +74,5 @@ Supports platform journey P05 and USER-WP-0030-T03. Add an exclusive mounted adm
|
|||
All Go regression/conformance suites pass, including five new renewal/validation tests with invalid-source subcases. Added exact-commit authentication acceptance CI. Provider-mounted credential delivery and effective optional policy remain gated separately.
|
||||
|
||||
Consumer source 632b1f1 deployed and Ready 1/1; CI, four provider HTTP checks and twelve live browser checks passed. See docs/credential-renewal-release-2026-09-13.md. T02/T03 retain actual credential delivery and live recovery/policy acceptance.
|
||||
|
||||
2026-09-13 custody activation supersedes the earlier owner-handoff gate: the new factor service is live and renewable. T02/T03 now track effective policy/onboarding acceptance, not missing credential ownership.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue