AnchorWrongKeyHandle (Bounded Authority Report Adapter v0.5.0)

Copy Markdown View Source

key_identity/1 + public_key/1 return key A's material, but sign/2 signs with a DIFFERENT key B (a rotation/misconfiguration race). The verify_signature guard in the shared signing tail must reject this -> :signing_failed.

Summary

Functions

key_identity(arg)

public_key(arg)

sign(message, handle)

thumbprint(arg)