Establish scoped KeyCape factor custody and verified automatic renewal

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
tegwick 2026-09-13 16:25:33 +02:00
parent fd34ac98f0
commit 74b4f7f1bc

View file

@ -33,17 +33,18 @@ Validation: `go test ./...` and `git diff --check` passed on 2026-09-13. See doc
```task
id: KEY-WP-0035-T02
status: wait
status: progress
priority: high
state_hub_task_id: "b066a273-f91c-50ee-b497-a39eace03b3a"
```
Live factor-read credentials return HTTP 401. The owner route
net-kingdom-privacyidea-admin-token is non-resolvable pending railiance-platform's
approved custody/renewal contract (NK-WP-0033). Native credential handoff required;
no secrets in work records. Do not enable the policy before lookup is verified.
Prepare exact byte-preserving client migration after the provider contract is
available; deploy digest-pinned source and run no-factor/enrolled/error checks.
Factor lookup restored on 2026-09-13 through the new dedicated service lane
RPF-WP-0040 / CCR-2026-0023. Native ESO delivery, scoped provider user lookup,
renewal and mounted replacement passed. KeyCape now uses adminTokenFile; other
configuration and current MFA policy were preserved. Historical NK-WP-0033
resolver lanes remain separate. The remaining T02 work is the exact scoped
client migration and no-factor/enrolled/error/step-up acceptance before enabling
optional policy. See railiance-platform/docs/evidence/2026-09-13-keycape-factor-custody.md.
## Verify optional enrollment and account management access
@ -73,3 +74,5 @@ Supports platform journey P05 and USER-WP-0030-T03. Add an exclusive mounted adm
All Go regression/conformance suites pass, including five new renewal/validation tests with invalid-source subcases. Added exact-commit authentication acceptance CI. Provider-mounted credential delivery and effective optional policy remain gated separately.
Consumer source 632b1f1 deployed and Ready 1/1; CI, four provider HTTP checks and twelve live browser checks passed. See docs/credential-renewal-release-2026-09-13.md. T02/T03 retain actual credential delivery and live recovery/policy acceptance.
2026-09-13 custody activation supersedes the earlier owner-handoff gate: the new factor service is live and renewable. T02/T03 now track effective policy/onboarding acceptance, not missing credential ownership.