From 8607d2111076b2f49d7326e24d2ad3810117eef8 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 00:36:30 +0200 Subject: [PATCH] Design 24: pair credentials are sealed to the operator too --- 03-DESIGN/01-to-be/24-the-secrets-vault.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/03-DESIGN/01-to-be/24-the-secrets-vault.md b/03-DESIGN/01-to-be/24-the-secrets-vault.md index 9b1070e..ff05586 100644 --- a/03-DESIGN/01-to-be/24-the-secrets-vault.md +++ b/03-DESIGN/01-to-be/24-the-secrets-vault.md @@ -108,9 +108,11 @@ foundation is raised with, so the mesh is handed over with nothing well-known in the installer's and is not yet built; until it is, the fixed credentials are the as-is and are said so in [21](21-the-installation-in-full.md). -What is not yet sealed to the operator: a module's vault-provided secret — the pair credential of -[13](13-credentials-and-their-rotation.md). That is the next increment, the same column and the -same call on the pair table. +A module's vault-provided secret — the pair credential of +[13](13-credentials-and-their-rotation.md) — is sealed to the operator the same way, as is every +credential a provider grants; the export names each entry by the node and module that hold it and +the name they know it by, and says whether it is a module's own secret or a pair credential, so +recovery addresses both alike. ## Beyond generate and hold