noCV
DART-107 · Control change and failure

Revoke a compromised signing identity without deleting history

Practice briefStoryExpert

A development signing key is declared compromised, and the cleanup proposal deletes every artifact it signed, including investigation records.

Focused work estimate
6h + prerequisites
Priority in the scenario
High
Engineering practice
Key revocation · Temporal policy · Audit

Estimated field mix

  • DevOps65%
  • Security35%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional command-line product publishes local package archives. Builds contain timestamps, checksums are copied without provenance, and cleanup can delete the only rollback artifact. Use generated source trees, ephemeral development signing keys, and local object storage; no public registry or production key is supplied.

Setup prerequisites

  • Content hashing
  • Archive formats
  • Release metadata

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Revocation records key identity, effective scope, time, and reason
  • Verification distinguishes signed-before, signed-after, and explicitly revoked artifacts
  • Historical metadata remains inspectable and immutable

Implementation constraints

  • Use ephemeral fixture keys; do not claim real-world trust without a provisioned signer and policy.

Verification to include

  • Verify artifacts on both sides of a declared rotation under policy.
  • Present an artifact signed after compromise and confirm promotion denial without deletion.

Deliverables

  • Signing revocation policy and temporal tests

Rollout and recovery

Block new promotion first, then review already promoted fixture artifacts.

Value of the work

For the engineer: Practice reproducible artifacts, provenance validation, signing-key isolation and retention safety.

For the team: Review a supply path that can trace, verify, retain, and revoke artifacts without relying on mutable names.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.