Skip to content

Rotate legacy login access exposed in prior documentation #9

Description

@ReidSurmeier

A legacy login credential was printed in a previously public README revision. The current documentation removes the value, but documentation cleanup does not revoke access.

Security work:

  • identify every installation and account for which the former credential may still work
  • rotate or disable password login through an approved recovery path
  • prefer verified key-only or tailnet-scoped access where compatible with field recovery
  • confirm access with a fresh remote login before ending any rollback window
  • store replacement credentials only in the approved password manager

Acceptance criteria:

  • the former credential no longer authenticates anywhere in scope
  • at least one approved recovery path is verified per live installation
  • no credential values are posted to this issue, repository, logs, or screenshots
  • NETWORKING.md and RECOVERY.md describe credential retrieval without embedding secrets.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingready-for-humanRequires physical, artistic, rights, or safety judgment

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions