Record final KeyCape recovery receipt
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
codex 2026-08-23 14:51:50 +02:00
parent 4619b8e08e
commit 18d61cd6a0
3 changed files with 28 additions and 14 deletions

View file

@ -25,13 +25,13 @@
},
"post_rotation_observation": {
"jwks_kid": "key-1",
"jwks_sha256": "3d46c07b649432eb41112b9e5f5a929460027766127d1eb419ebac8eb9858c06",
"jwks_sha256": "c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156",
"observed_at": "2026-08-23",
"source_revision_binding": "REQUIRED",
"downstream_refresh_confirmation": "REQUIRED"
"source_revision_binding": "93704fd2424503007c20b458b62a7f7d994bb288",
"downstream_refresh_confirmation": "keycape-authelia-lldap-privacyidea-identity-provisioner-ready-1-1"
},
"revisions": {
"key_cape": "REQUIRED",
"key_cape": "93704fd2424503007c20b458b62a7f7d994bb288",
"net_kingdom": "REQUIRED",
"railiance_platform": "453fed3"
},
@ -45,8 +45,8 @@
"abort": "root-admin"
},
"acknowledgements": {
"key_cape_message_id": null,
"net_kingdom_message_id": null
"key_cape_message_id": "05b49688-76a8-4be9-a00d-95408c798697",
"net_kingdom_message_id": "71b1008a-7fd7-4500-85c6-e8893a6d80d4"
},
"authorization": {
"human_go": true,

View file

@ -80,6 +80,17 @@ A fresh public JWKS read on 2026-08-23 found kid `key-1` and SHA-256
Treat this as an observation only until KeyCape binds it to the source
revision and confirms downstream cache refresh.
KeyCape subsequently supplied source revision
`93704fd2424503007c20b458b62a7f7d994bb288`, final public JWKS kid `key-1`,
and SHA-256
`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`.
KeyCape, Authelia, LLDAP, privacyIDEA, and identity-provisioner were reported
Ready 1/1, with replacement/negative checks recorded. The persistent
privacyIDEA `lldap-coulomb` resolver remains an attended provider-admin
follow-up and is explicitly not complete; do not declare the incident closed
or perform further bundle mutation until that owner action is separately
authorized and evidenced.
## Ownership
| Boundary | Owner | Required contribution |

View file

@ -57,15 +57,18 @@ status: progress
priority: high
```
KeyCape acknowledged emergency rotation with deliberate JWT invalidation and
JWKS/cache refresh required (message `aeb216b5-9f1b-404b-a483-fb08a00a49b1`),
but has not yet supplied the non-secret client-config revision or a post-change
JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence
at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`), including the
expiry-based privacyIDEA predecessor decision. The digest-bound approval
KeyCape supplied source revision `93704fd2424503007c20b458b62a7f7d994bb288`,
post-rotation JWKS SHA-256
`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`, and
rollout/predecessor evidence (messages `05b49688-76a8-4be9-a00d-95408c798697`
and `538046b9-2dbb-4704-b7b6-2dbf16c5e3bb`). NetKingdom pinned the value-safe
dependency and provider sequence at `c24d67b` (message
`71b1008a-7fd7-4500-85c6-e8893a6d80d4`). The persistent privacyIDEA
`lldap-coulomb` resolver still requires an attended provider-admin update, so
T04 remains blocked for that explicit follow-up. The digest-bound approval
template is published at
`docs/keycape-exposure-rotation-approval.example.json`; all authorization
gates remain false pending the missing receipts and an exact human GO.
`docs/keycape-exposure-rotation-approval.example.json`; no additional Secret
apply is authorized by this receipt.
## T04 — Execute the attended rotation