diff --git a/workplans/KEY-WP-0035-optional-mfa.md b/workplans/KEY-WP-0035-optional-mfa.md index 7d7762b..f70b93f 100644 --- a/workplans/KEY-WP-0035-optional-mfa.md +++ b/workplans/KEY-WP-0035-optional-mfa.md @@ -33,17 +33,18 @@ Validation: `go test ./...` and `git diff --check` passed on 2026-09-13. See doc ```task id: KEY-WP-0035-T02 -status: wait +status: progress priority: high state_hub_task_id: "b066a273-f91c-50ee-b497-a39eace03b3a" ``` -Live factor-read credentials return HTTP 401. The owner route -net-kingdom-privacyidea-admin-token is non-resolvable pending railiance-platform's -approved custody/renewal contract (NK-WP-0033). Native credential handoff required; -no secrets in work records. Do not enable the policy before lookup is verified. -Prepare exact byte-preserving client migration after the provider contract is -available; deploy digest-pinned source and run no-factor/enrolled/error checks. +Factor lookup restored on 2026-09-13 through the new dedicated service lane +RPF-WP-0040 / CCR-2026-0023. Native ESO delivery, scoped provider user lookup, +renewal and mounted replacement passed. KeyCape now uses adminTokenFile; other +configuration and current MFA policy were preserved. Historical NK-WP-0033 +resolver lanes remain separate. The remaining T02 work is the exact scoped +client migration and no-factor/enrolled/error/step-up acceptance before enabling +optional policy. See railiance-platform/docs/evidence/2026-09-13-keycape-factor-custody.md. ## Verify optional enrollment and account management access @@ -73,3 +74,5 @@ Supports platform journey P05 and USER-WP-0030-T03. Add an exclusive mounted adm All Go regression/conformance suites pass, including five new renewal/validation tests with invalid-source subcases. Added exact-commit authentication acceptance CI. Provider-mounted credential delivery and effective optional policy remain gated separately. Consumer source 632b1f1 deployed and Ready 1/1; CI, four provider HTTP checks and twelve live browser checks passed. See docs/credential-renewal-release-2026-09-13.md. T02/T03 retain actual credential delivery and live recovery/policy acceptance. + +2026-09-13 custody activation supersedes the earlier owner-handoff gate: the new factor service is live and renewable. T02/T03 now track effective policy/onboarding acceptance, not missing credential ownership.