Opened 7 years ago
Last modified 3 years ago
#61 ON HOLD fault
FOUNDER-TIER service credential rotation overdue since 2019 — no one holds the tier
| Reported by: | People & Places | Owned by: | M. Ross (Infrastructure) |
|---|---|---|---|
| Priority: | P1 | Milestone: | |
| Component: | Registry Services / PKI | Version: | |
| Keywords: | Cc: | ||
| Desk: | Estate & Systems | Legacy ref: | RS-13355 |
Description
The FOUNDER-TIER service credential on the registry directory — the top-level account that provisions and consolidates corporate identities — was diarised for rotation in 2019 and never rotated. The catch: rotating FOUNDER-TIER requires FOUNDER-TIER, and no current member of staff holds it. The tier sits above BUILTIN\LocalOperator and the cached entitlements this console falls back to, so the degraded session cannot even see it, let alone act on it. The credential is years past its rotation window. Nobody can rotate it and nobody can revoke it.
Attachments (0)
Change History (3)
comment:1 by , 7 years ago
comment:2 by , 7 years ago
So the one account that can stand up or rebuild any company in the register hasn't had its password changed since before the API died, and we can't change it either. Marvellous. Not DNS. Considerably worse than DNS.
comment:3 by , 3 years ago
FOUNDER-TIER still present, still unrotated, still unreachable from any current login. Out of scope for everyone. Left on hold.
Same story as the LDAPS cert (DEVCON-0770 / DEVCON-1042): diarised, never done. Except this one you can't fix by reissuing from the CA — you need FOUNDER-TIER to rotate FOUNDER-TIER, and nobody sitting here has ever held it. On the cached-entitlements session it doesn't even render. It's above our heads, literally.