Skip to content

Implement runtime key rotation behavior #73

Description

@coreytshaffer

Summary

Follow-up from #4.

The current identity system has documented rotation/recovery policy, but runtime key rotation behavior should remain separate from the identity MVP.

Scope

  • Define how an active agent identity rotates to a new key.
  • Preserve old public key metadata long enough to verify historical ledger events.
  • Ensure revoked or superseded keys cannot sign new events.
  • Keep private key material local and gitignored.

Non-goals

  • No remote key custody.
  • No cloud worker private keys.
  • No public blockchain.
  • No automatic trust escalation.

Acceptance criteria

  • Rotation behavior is documented before implementation.
  • Historical signed events remain verifiable after rotation.
  • Superseded/revoked keys fail new signing authorization.
  • Tests cover rotation success, stale-key rejection, and historical verification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions