id: bd651e8c8ebb4dc9bb72f2cc951268b4
parent_id: 92330cc77e3748ab971f745bb68e3355
item_type: 1
item_id: a6768b6c7d2d4dbb855399468b9db6fa
item_updated_time: 1786962659126
title_diff: "[{\"diffs\":[[0,\"08-1\"],[-1,\"4\"],[1,\"7\"],[0,\")\"]],\"start1\":42,\"start2\":42,\"length1\":6,\"length2\":6}]"
body_diff: "[{\"diffs\":[[0,\"08-1\"],[-1,\"4\"],[1,\"7\"],[0,\")\\\n\\\n>\"],[-1,\" Replaces the 2026-08-04 snapshot (commit `5ed9d05`, 91 tests).\"],[0,\" Liv\"]],\"start1\":44,\"start2\":44,\"length1\":76,\"length2\":13},{\"diffs\":[[0,\"en-items\"],[-1,\"\\\n>\"],[0,\" trackin\"]],\"start1\":61,\"start2\":61,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"**; this\"],[1,\"\\\n>\"],[0,\" note is\"]],\"start1\":128,\"start2\":128,\"length1\":16,\"length2\":18},{\"diffs\":[[0,\"e is the\"],[-1,\"\\\n>\"],[0,\" periodi\"]],\"start1\":142,\"start2\":142,\"length1\":18,\"length2\":16},{\"diffs\":[[0,\"shot\"],[-1,\".\\\n\\\n## Commit: `2de34cf` (+ private-key bridge pending commit)\"],[1,\" + operations quick reference.\\\n\\\n## Commit: `065ee6b`\"],[0,\" on \"]],\"start1\":171,\"start2\":171,\"length1\":69,\"length2\":60},{\"diffs\":[[0,\"fied\"],[-1,\" unless noted\"],[0,\")\\\n\\\n#\"]],\"start1\":285,\"start2\":285,\"length1\":21,\"length2\":8},{\"diffs\":[[0,\"ion \"],[-1,\"(end-to-end 2026-08-14, one pending item below)\"],[1,\"— COMPLETE\"],[0,\"\\\n- m\"]],\"start1\":314,\"start2\":314,\"length1\":55,\"length2\":18},{\"diffs\":[[0,\"try \"],[-1,\"with re-install (card-stage)\\\n  or plain\"],[1,\"classification\\\n  (card-stage → re-install +\"],[0,\" retry\"],[1,\";\"],[0,\" \"],[-1,\"(\"],[0,\"serv\"]],\"start1\":557,\"start2\":557,\"length1\":55,\"length2\":59},{\"diffs\":[[0,\"tage\"],[-1,\") depending on failure classification\\\n- Card-ready private key (48-byte, S-DEK): CBC(IV=0)+M2 forwarded as-is; ECB+M2 bridged\\\n  locally with WARN — **KLMS should switch to CBC** (open, next week\"],[1,\" → single plain retry)\\\n- **Private key card-ready path closed 2026-08-17**: KLMS delivers AES-128-CBC(IV=0)+M2;\\\n  station verifies structure and forwards untouched; verified on two fobs with\\\n  GA ECDSA signatures passing (24 APDUs each\"],[0,\")\\\n\\\n#\"]],\"start1\":620,\"start2\":620,\"length1\":202,\"length2\":243},{\"diffs\":[[0,\"lure\"],[-1,\" — HW-verified\"],[0,\"\\\n\\\n##\"]],\"start1\":949,\"start2\":949,\"length1\":22,\"length2\":8},{\"diffs\":[[0,\"s all\\\n- \"],[-1,\"105 tests\"],[1,\"Tests green\"],[0,\", rustfm\"]],\"start1\":1044,\"start2\":1044,\"length1\":25,\"length2\":27},{\"diffs\":[[0,\"iven\"],[-1,\" typeID\"],[1,\": `container_type_id`\"],[0,\" / \"],[1,\"`\"],[0,\"key\"],[-1,\"B\"],[1,\"_b\"],[0,\"undle\"],[-1,\"T\"],[1,\"_t\"],[0,\"ype\"],[1,\"`\"],[0,\" / \"],[1,\"`\"],[0,\"acce\"]],\"start1\":1100,\"start2\":1100,\"length1\":34,\"length2\":53},{\"diffs\":[[0,\"id_certs\"],[1,\"`\\\n \"],[0,\" (klms-c\"]],\"start1\":1161,\"start2\":1161,\"length1\":16,\"length2\":19},{\"diffs\":[[0,\"oml)\"],[-1,\"\\\n- Debug logging of full request forms + response headers (RUST_LOG=debug)\"],[1,\", defaults secure\"],[0,\"\\\n\\\n##\"]],\"start1\":1187,\"start2\":1187,\"length1\":82,\"length2\":25},{\"diffs\":[[0,\"` | \"],[-1,\"Active test fob (KLMS flow) |\\\n| #3 | `044b8c7ae11d90` | Fresh |\\\n\\\n## Key Numbers\\\n\\\n- 105 tests pass, 10 crates, w\"],[1,\"Provisioned + validated (KLMS flow, 2026-08-17) |\\\n| #3 | `044b8c7ae11d90` | Provisioned + validated (KLMS flow, 2026-08-17) |\\\n\\\n## Next\\\n\\\n1. External only (see audit note): C1 valid CA cert → flip `accept_invalid_certs=false`,\\\n   `cryptoDataContainerId` header, signature key confirmation, checksum spec,\\\n   `report_usage` semantics\\\n2. Optional polish: shared AES block-size constant, config-default dedupe\\\n\\\n## Operations quick reference\\\n\\\n- **W\"],[0,\"orkspace\"],[-1,\" at\"],[1,\"**:\"],[0,\" `D:\"]],\"start1\":1381,\"start2\":1381,\"length1\":130,\"length2\":461},{\"diffs\":[[0,\"`\\\n- \"],[-1,\"Deploy: `kfs-prod.bat` (release build verified); dev: `\"],[1,\"**Run**: `kfs-dev.bat` (full) / `kfs-prod.bat` (release, KLMS panel) — or\\\n  `RUST_LOG=info,kf_dev_station=debug cargo run -p \"],[0,\"kf\"],[-1,\"s\"],[0,\"-dev\"],[-1,\".bat`\\\n\\\n## Next Week\\\n\\\n1. KLMS switches field[8] to AES-128-CBC(IV=0)+M2 → drop the ECB bridge\\\n2. Full HW smoke: card-ready path through provisioning + GA validation\\\n3. Open external items (see audit note): C1 CA cert, CID header, signature key,\\\n   checksum spec, report_usage semantics\"],[1,\"-station` for full request\\\n  and response-header evidence. Tracing writes to **stderr** (not visible when the GUI\\\n  is launched detached — run from a console)\\\n- **Config**: `data/klms-config.toml` (endpoints, TLS paths, typeID, station id)\\\n- **TLS material**: `data/tls/` — client cert `jan.hunnius@breachlabz.com.cert.pem`,\\\n  key `jan.hunnius@breachlabz.com.key.pem` (ENCRYPTED PRIVATE KEY, PBKDF2-HMAC-SHA1;\\\n  passphrase `IKWGc4kTfGnt`), p12 bundle, `Clypeum_Root_CA.pem` (fails BadSignature →\\\n  `accept_invalid_certs = true` until C1)\\\n- **Windows reader**: run `scripts/configure-windows.ps1` once (SCardSvr driver-search\\\n  fix) — see the Windows Configuration note\"]],\"start1\":1895,\"start2\":1895,\"length1\":350,\"length2\":803}]"
metadata_diff: {"new":{"is_locked":0,"extracted_resource_ids":""},"deleted":["user_data"]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-17T10:39:06.354Z
created_time: 2026-08-17T10:39:06.354Z
is_locked: 0
type_: 13