From 18d61cd6a0f100dc3ad5644421779b0308332ec2 Mon Sep 17 00:00:00 2001 From: codex Date: Sun, 23 Aug 2026 14:51:50 +0200 Subject: [PATCH] Record final KeyCape recovery receipt Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093 --- ...pe-exposure-rotation-approval.example.json | 12 ++++++------ docs/keycape-live-secret-exposure-recovery.md | 11 +++++++++++ ...9-keycape-live-secret-exposure-recovery.md | 19 +++++++++++-------- 3 files changed, 28 insertions(+), 14 deletions(-) diff --git a/docs/keycape-exposure-rotation-approval.example.json b/docs/keycape-exposure-rotation-approval.example.json index f383cb4..93a34c5 100644 --- a/docs/keycape-exposure-rotation-approval.example.json +++ b/docs/keycape-exposure-rotation-approval.example.json @@ -25,13 +25,13 @@ }, "post_rotation_observation": { "jwks_kid": "key-1", - "jwks_sha256": "3d46c07b649432eb41112b9e5f5a929460027766127d1eb419ebac8eb9858c06", + "jwks_sha256": "c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156", "observed_at": "2026-08-23", - "source_revision_binding": "REQUIRED", - "downstream_refresh_confirmation": "REQUIRED" + "source_revision_binding": "93704fd2424503007c20b458b62a7f7d994bb288", + "downstream_refresh_confirmation": "keycape-authelia-lldap-privacyidea-identity-provisioner-ready-1-1" }, "revisions": { - "key_cape": "REQUIRED", + "key_cape": "93704fd2424503007c20b458b62a7f7d994bb288", "net_kingdom": "REQUIRED", "railiance_platform": "453fed3" }, @@ -45,8 +45,8 @@ "abort": "root-admin" }, "acknowledgements": { - "key_cape_message_id": null, - "net_kingdom_message_id": null + "key_cape_message_id": "05b49688-76a8-4be9-a00d-95408c798697", + "net_kingdom_message_id": "71b1008a-7fd7-4500-85c6-e8893a6d80d4" }, "authorization": { "human_go": true, diff --git a/docs/keycape-live-secret-exposure-recovery.md b/docs/keycape-live-secret-exposure-recovery.md index e601bec..f96045b 100644 --- a/docs/keycape-live-secret-exposure-recovery.md +++ b/docs/keycape-live-secret-exposure-recovery.md @@ -80,6 +80,17 @@ A fresh public JWKS read on 2026-08-23 found kid `key-1` and SHA-256 Treat this as an observation only until KeyCape binds it to the source revision and confirms downstream cache refresh. +KeyCape subsequently supplied source revision +`93704fd2424503007c20b458b62a7f7d994bb288`, final public JWKS kid `key-1`, +and SHA-256 +`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`. +KeyCape, Authelia, LLDAP, privacyIDEA, and identity-provisioner were reported +Ready 1/1, with replacement/negative checks recorded. The persistent +privacyIDEA `lldap-coulomb` resolver remains an attended provider-admin +follow-up and is explicitly not complete; do not declare the incident closed +or perform further bundle mutation until that owner action is separately +authorized and evidenced. + ## Ownership | Boundary | Owner | Required contribution | diff --git a/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md b/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md index bf3b625..82ea46e 100644 --- a/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md +++ b/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md @@ -57,15 +57,18 @@ status: progress priority: high ``` -KeyCape acknowledged emergency rotation with deliberate JWT invalidation and -JWKS/cache refresh required (message `aeb216b5-9f1b-404b-a483-fb08a00a49b1`), -but has not yet supplied the non-secret client-config revision or a post-change -JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence -at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`), including the -expiry-based privacyIDEA predecessor decision. The digest-bound approval +KeyCape supplied source revision `93704fd2424503007c20b458b62a7f7d994bb288`, +post-rotation JWKS SHA-256 +`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`, and +rollout/predecessor evidence (messages `05b49688-76a8-4be9-a00d-95408c798697` +and `538046b9-2dbb-4704-b7b6-2dbf16c5e3bb`). NetKingdom pinned the value-safe +dependency and provider sequence at `c24d67b` (message +`71b1008a-7fd7-4500-85c6-e8893a6d80d4`). The persistent privacyIDEA +`lldap-coulomb` resolver still requires an attended provider-admin update, so +T04 remains blocked for that explicit follow-up. The digest-bound approval template is published at -`docs/keycape-exposure-rotation-approval.example.json`; all authorization -gates remain false pending the missing receipts and an exact human GO. +`docs/keycape-exposure-rotation-approval.example.json`; no additional Secret +apply is authorized by this receipt. ## T04 — Execute the attended rotation