Record final KeyCape recovery receipt
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
codex 2026-08-23 14:51:50 +02:00
parent 4619b8e08e
commit 18d61cd6a0
3 changed files with 28 additions and 14 deletions

View file

@ -80,6 +80,17 @@ A fresh public JWKS read on 2026-08-23 found kid `key-1` and SHA-256
Treat this as an observation only until KeyCape binds it to the source
revision and confirms downstream cache refresh.
KeyCape subsequently supplied source revision
`93704fd2424503007c20b458b62a7f7d994bb288`, final public JWKS kid `key-1`,
and SHA-256
`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`.
KeyCape, Authelia, LLDAP, privacyIDEA, and identity-provisioner were reported
Ready 1/1, with replacement/negative checks recorded. The persistent
privacyIDEA `lldap-coulomb` resolver remains an attended provider-admin
follow-up and is explicitly not complete; do not declare the incident closed
or perform further bundle mutation until that owner action is separately
authorized and evidenced.
## Ownership
| Boundary | Owner | Required contribution |