diff --git a/workplans/RPF-WP-0040-keycape-factor-credential-custody.md b/workplans/RPF-WP-0040-keycape-factor-credential-custody.md index 02d37da..e05104f 100644 --- a/workplans/RPF-WP-0040-keycape-factor-credential-custody.md +++ b/workplans/RPF-WP-0040-keycape-factor-credential-custody.md @@ -9,6 +9,7 @@ owner: codex topic_slug: financials created: "2026-09-13" updated: "2026-09-13" +state_hub_workstream_id: "fa606195-422d-5121-be63-38192380b1eb" --- User authorized establishing custody/delivery on 2026-09-13 and offered attended administrative authentication. Supports USER-WP-0030-T03 and KEY-WP-0035-T02. Existing incident lanes are not silently repurposed. @@ -19,6 +20,7 @@ User authorized establishing custody/delivery on 2026-09-13 and offered attended id: RPF-WP-0040-T01 status: done priority: high +state_hub_task_id: "3faba86f-795b-5140-a1ed-87ce0c3c1616" ``` New KV v2 path platform/workloads/net-kingdom/keycape-factor-read, field TOKEN, provider expiry metadata. Reader role binds only sso/keycape-factor-eso, audience openbao, exact-path read policy and fifteen-minute OpenBao tokens. Attended admin metadata apply, exact readback and capability checks. No wildcard secret access or secret value in output. @@ -29,6 +31,7 @@ New KV v2 path platform/workloads/net-kingdom/keycape-factor-read, field TOKEN, id: RPF-WP-0040-T02 status: done priority: high +state_hub_task_id: "04cf9de8-0306-595f-af3a-bfa9046a25ea" ``` Create dedicated privacyIDEA keycape-factor-reader with coulomb tokenlist permission. Preserve existing admin rights; baseline has no admin policies. Store renewable issuer credential separately from the delivered JWT. Use protected stdin and in-memory handling, provider-issued JWT with expiry, positive cross-user scope and negative admin policy-read checks. No personal admin password in runtime. @@ -39,6 +42,7 @@ Create dedicated privacyIDEA keycape-factor-reader with coulomb tokenlist permis id: RPF-WP-0040-T03 status: done priority: high +state_hub_task_id: "b60dc6dc-628b-5ffa-9e5c-e897365cd90f" ``` Deliver via namespace-scoped ESO, activate KeyCape adminTokenFile with byte-preserving config CAS, schedule renewal before expiry and verify mounted reload and native scope. Predecessor expiry/revocation and recovery drills remain T04. Verify effective scope and real factor acceptance before optional client policy. Preserve existing incident residuals in NK-WP-0033. @@ -54,6 +58,7 @@ rolled out Ready 1/1 without changing MFA policy or signing/client secrets. id: RPF-WP-0040-T04 status: todo priority: high +state_hub_task_id: "c7803984-e96d-5503-9214-6dc2a1a84fbe" ``` Exercise genuine JWT expiry, provider-side permission withdrawal and recovery