Skip to content

Rotate legacy login access exposed in prior documentation #9

Description

@ReidSurmeier

A legacy login credential was printed in a previously public README revision. The current documentation removes the value, but documentation cleanup does not revoke access.

Security work:

  • identify every installation and account for which the former credential may still work
  • rotate or disable password login through an approved recovery path
  • prefer verified key-only or tailnet-scoped access where compatible with field recovery
  • confirm access with a fresh remote login before ending any rollback window
  • store replacement credentials only in the approved password manager

Acceptance criteria:

  • the former credential no longer authenticates anywhere in scope
  • at least one approved recovery path is verified per live installation
  • no credential values are posted to this issue, repository, logs, or screenshots
  • NETWORKING.md and RECOVERY.md describe credential retrieval without embedding secrets.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingready-for-humanRequires physical, artistic, rights, or safety judgment

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions