Record KeyCape exposure owner receipts
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
codex 2026-08-23 14:37:36 +02:00
parent d18649fc6e
commit 7ce3bc8380
2 changed files with 23 additions and 6 deletions

View file

@ -12,7 +12,7 @@ updated: "2026-08-23"
related:
- KEY-WP-0011
origin: routed
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d and acf98be3-ff6b-4270-bd21-0193bebd806b"
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4"
---
# RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
@ -57,10 +57,15 @@ status: progress
priority: high
```
KeyCape must pin the non-secret client-config revision and either a unique-kid
overlap implementation or the exact immediate-invalidation/cache-refresh
procedure. NetKingdom must pin the LLDAP, Authelia, and privacyIDEA provider
steps. Railiance-platform must then issue one digest-bound approval template.
KeyCape acknowledged emergency rotation with deliberate JWT invalidation and
JWKS/cache refresh required (message `aeb216b5-9f1b-404b-a483-fb08a00a49b1`),
but has not yet supplied the non-secret client-config revision or a post-change
JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence
at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`), including the
expiry-based privacyIDEA predecessor decision. The digest-bound approval
template is published at
`docs/keycape-exposure-rotation-approval.example.json`; all authorization
gates remain false pending the missing receipts and an exact human GO.
## T04 — Execute the attended rotation