|
Live verify result: PKI identity is correct on both DCs; only the mode defect remains
Ran scripts/octavia-pki.sh verify against both real PKI sets on the headend. Both DCs: 23 assertions PASS, 3 FAIL, and the 3 are the same already-known mode defect. Every IDENTITY assertion passes. CA subjects name the correct DC on both, so DC_LABEL was set on both runs and the unguarded-variable risk did not bite. The chain verifies against the CONTROLLER CA and correctly does NOT verify against the issuing CA -- proving two distinct trust domains, not merely that one link works. The SAN set carries two DNS names plus each DC's OWN provider v4 and v6 addresses, so F8's SAN-less failure mode did not occur and the D-109 v6-SAN ruling is satisfied in the artifact rather than only in the decision. Overlay mode, key count, ASCII and gitignore all pass, and per-DC independence holds. The only outstanding defect is the three certificates per DC at mode 664. Remediation is a chmod and remains operator-gated. The gate demonstrated teeth on live data rather than only in fixtures: it failed the real defects while passing everything genuinely correct. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|