Record verified production Clock custody and authority acceptance
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
parent
e70ef2f32a
commit
3bd3a2e87b
5 changed files with 102 additions and 8 deletions
|
|
@ -34,3 +34,23 @@ Rotation is a separate explicit operation: stop the authority, CAS against the
|
|||
known current custody version, replace the host key atomically, and distribute
|
||||
new public key/epoch trust before resuming clients. This initial-admission helper
|
||||
deliberately does not implement rotation or overwrite keys.
|
||||
|
||||
## Accepted production deployment
|
||||
|
||||
Version 1 custody and native workstation samples passed on 2026-09-15. See
|
||||
`docs/evidence/2026-09-15-railiance-clock-host-custody.json` and
|
||||
`docs/evidence/2026-09-15-railiance-clock-production.json`.
|
||||
Use the documented private OpenBao endpoint `http://127.0.0.1:18200` for the
|
||||
attended envelope: the configured public hostname presented an untrusted
|
||||
certificate during deployment. TLS verification was not disabled.
|
||||
|
||||
Authority endpoint on Railiance01: `http://127.0.0.1:8787/v1/time-samples`;
|
||||
readiness: `http://127.0.0.1:8787/readyz`. Workstations use an authenticated SSH
|
||||
loopback connection and separately admitted public key/epoch. Trust files last
|
||||
at most 15 minutes and do not survive a workstation boot. Optional integrations
|
||||
are not globally enabled by this deployment; operational trust refresh remains
|
||||
in RCLK-WP-0005-T06 and consumer adoption in RCLK-WP-0004.
|
||||
|
||||
The health export sandbox allows read-only adjtimex, which ProtectClock would
|
||||
block even with modes=0. Empty bounding/ambient capability sets deny clock writes.
|
||||
The authority keeps ProtectClock enabled.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue