420Storage credential rotation and recovery qualification¶
SR-10.5 qualifies operational credential rotation and compromise recovery for the Resource Network without moving credential authority into canonical storage state.
Security boundary¶
Service credentials, bearer tokens, session material and signing secrets remain operational secrets. They must never be written into manifests, placements, agreements, proofs, settlement records, public status responses or ordinary telemetry.
The production credential manager stores only SHA-256 digests for validation and exposes only service identity, generation, lifecycle state, overlap expiry and a short non-secret fingerprint in qualification snapshots. Deployments must use high-entropy credentials generated by an approved secret manager; human-memorable passwords are not appropriate service credentials.
Rotation model¶
A service credential begins at generation 1. Rotation proves possession of the current credential before installing the next generation.
Two modes are supported:
- zero-overlap rotation immediately revokes the prior generation;
- bounded-overlap rotation leaves only the immediately preceding generation valid until the configured expiry while the replacement is already active.
Expired overlap credentials fail validation deterministically.
Compromise and lost-credential recovery¶
For suspected compromise, operators revoke the service identity first. Revocation invalidates every known generation immediately. Recovery then installs a new generation only after all prior generations are revoked.
Recovery does not rewrite provider identity, node identity, manifests, placements, commitments, proofs or settlement history.
Qualification assertions¶
SR-10.5 tests require:
- rotation cannot proceed without proving the current credential;
- old credentials expire at the overlap boundary;
- zero-overlap rotation invalidates the old credential immediately;
- compromise revocation invalidates all known generations;
- recovery creates a new active generation without re-enabling compromised material;
- concurrent validation remains race-safe during rotation;
- redacted snapshots never contain raw credentials or bearer values.
Operator procedure¶
- Generate the replacement credential in the deployment secret manager.
- Select zero overlap for compromise response, or a short bounded overlap for planned rotation.
- Rotate one service identity at a time and validate the new generation before removing the prior secret from dependent services.
- Confirm the old generation is rejected after the overlap deadline.
- For compromise, revoke first, then recover with fresh material and restart/reload dependents as required.
- Capture only redacted generation/state evidence in qualification artifacts.
Launch evidence¶
SR-10.9 and SR-10.10 evidence may contain service IDs, generation numbers, lifecycle state and redacted fingerprints. It must not contain raw credentials, Authorization headers, session tokens, signing keys or secret-manager payloads.