ADR 0114: a two-party credential rotates over two logins
Graduates research 016. Retiring a login is separated from removing a consumer, which closes a data-loss path in five providers; single-party secrets rotate in place; the number of parties decides, not the provider.
This commit is contained in:
@@ -164,10 +164,12 @@ the change using the old value. Where no provisioner can make it, the requiremen
|
||||
rotatable by the mesh**, and a rotation request is refused, saying why, rather than restarting a service
|
||||
that would carry on with the old value.
|
||||
|
||||
**How old and new change over is not decided here.** Three mechanisms were measured against every
|
||||
provider's code in [research 016](../01-RESEARCH/016-how-a-credential-can-be-rotated/00-overview.md):
|
||||
in place, as the controller's `rotate` does today; two secrets on one login; and two logins over one
|
||||
resource. Its findings bound the choice:
|
||||
**How old and new change over is decided in [ADR
|
||||
0114](0114-a-shared-credential-rotates-over-two-logins.md).** Three mechanisms were measured against
|
||||
every provider's code in [research
|
||||
016](../01-RESEARCH/016-how-a-credential-can-be-rotated/00-overview.md): in place, as the controller's
|
||||
`rotate` does today; two secrets on one login; and two logins over one resource. Its findings bound the
|
||||
choice:
|
||||
|
||||
- every credential provider already re-applies a password in place, so today's rotation works, with a
|
||||
window in which a consumer cannot authenticate;
|
||||
@@ -178,8 +180,8 @@ resource. Its findings bound the choice:
|
||||
- every backend can give two logins the same rights over one resource, once the adapter separates the
|
||||
resource from the login.
|
||||
|
||||
The mechanism is decided in its own record, on those facts. Until then rotation stays as the
|
||||
controller implements it, in place, with its window stated.
|
||||
On those facts, 0114 rotates a credential two parties hold over two logins, rotates one a single
|
||||
party holds in place, and separates retiring a login from removing a consumer.
|
||||
|
||||
## What this changes in earlier records
|
||||
|
||||
@@ -215,7 +217,7 @@ On acceptance, each of these is superseded or amended by this record, not edited
|
||||
- Resolution expands per-consumer requirements from a provision's contract. The contract declares
|
||||
them, never the provider's code, so what a provider requires stays predictable from the catalogue.
|
||||
- A data provider's adapter gains a return value. What a credential provider's adapter must change for
|
||||
rotation is decided with the mechanism ([research 016](../01-RESEARCH/016-how-a-credential-can-be-rotated/03-the-options.md)).
|
||||
rotation is [ADR 0114](0114-a-shared-credential-rotates-over-two-logins.md)'s.
|
||||
- The broker's provisioner gains every bus account, and the controller loses five separate places it
|
||||
generates a secret today.
|
||||
- 54 modules move from own secrets to vault requirements. Six provider clients export a password
|
||||
|
||||
Reference in New Issue
Block a user