Record KeyCape exposure owner receipts
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
parent
d18649fc6e
commit
7ce3bc8380
2 changed files with 23 additions and 6 deletions
|
|
@ -12,7 +12,7 @@ updated: "2026-08-23"
|
|||
related:
|
||||
- KEY-WP-0011
|
||||
origin: routed
|
||||
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d and acf98be3-ff6b-4270-bd21-0193bebd806b"
|
||||
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4"
|
||||
---
|
||||
|
||||
# RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
|
||||
|
|
@ -57,10 +57,15 @@ status: progress
|
|||
priority: high
|
||||
```
|
||||
|
||||
KeyCape must pin the non-secret client-config revision and either a unique-kid
|
||||
overlap implementation or the exact immediate-invalidation/cache-refresh
|
||||
procedure. NetKingdom must pin the LLDAP, Authelia, and privacyIDEA provider
|
||||
steps. Railiance-platform must then issue one digest-bound approval template.
|
||||
KeyCape acknowledged emergency rotation with deliberate JWT invalidation and
|
||||
JWKS/cache refresh required (message `aeb216b5-9f1b-404b-a483-fb08a00a49b1`),
|
||||
but has not yet supplied the non-secret client-config revision or a post-change
|
||||
JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence
|
||||
at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`), including the
|
||||
expiry-based privacyIDEA predecessor decision. The digest-bound approval
|
||||
template is published at
|
||||
`docs/keycape-exposure-rotation-approval.example.json`; all authorization
|
||||
gates remain false pending the missing receipts and an exact human GO.
|
||||
|
||||
## T04 — Execute the attended rotation
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue