Module boundary
Any future production crypto needs a named module boundary, interface inventory, approved algorithms, parameters, and security-strength records.
FIPS, Keys, Randomness, and Non-Claims
Latticra records the evidence required before production cryptography, signing, key storage, FIPS/CMVP claims, randomness, or post-quantum migration wording can promote. It does not implement production crypto or grant signing authority.
Current Rule
The baseline names cryptographic module boundaries, approved algorithm and parameter inventories, key lifecycle contracts, randomness review, self-test behavior, sensitive-data handling, and post-quantum planning as prerequisites. Until those records are complete and validated, crypto-facing records remain metadata and non-claim language.
Any future production crypto needs a named module boundary, interface inventory, approved algorithms, parameters, and security-strength records.
Key types, generation, storage, access control, rotation, expiration, zeroization, compromise response, and metadata protection must be explicit.
Entropy source, DRBG or random-bit generator, startup self-tests, continuous checks, and failure behavior require written review.
Migration wording needs an inventory of affected algorithms, dependencies, transition rules, and operator-visible non-claims.
Current Snapshot
These fields are a claim boundary. They show that requirements are tracked, while production cryptography, signing authority, and FIPS claims remain unavailable.
Promotion Gate
A future cryptographic capability needs evidence that covers module scope, algorithm choices, key material, randomness, failure behavior, validation status, and public non-claims before it can affect release wording.
Baseline record, status record, guard script, source references, Seal metadata-only records, and public non-claim wording.
Module boundary, interface inventory, algorithm and parameter inventory, key lifecycle and storage contract, access control, zeroization, compromise response, entropy and DRBG review, self-test failure behavior, sensitive-data logging review, side-channel review, validation certificate or non-FIPS disclosure, post-quantum inventory, and operator-visible non-claims.
Production cryptography, FIPS/CMVP claims, release signing, update signing, receipt signing, key generation, key storage, key derivation, entropy collection, random-bit generation, post-quantum migration claims, and cryptographic module validation claims.
Seal Crypto Boundary
Seal can describe verification posture and denied authority, but the current records do not create a production signing path, key store, validated module, or runtime enforcement boundary.
The current crypto verify backend status is metadata-only and does not claim production verification.
Ed25519 records stay authority-neutral and do not create signing or update authority.
Signing, key material handling, key storage, key generation, and release/update signatures remain unavailable.
No runtime authority, FIPS claim, CMVP claim, production crypto enforcement, or external endorsement is granted.
Local Commands
These commands check that public records, status fields, and safety gates stay aligned. They do not generate keys, sign artifacts, collect entropy, or perform validation submissions.
sh scripts/test-cryptographic-assurance-key-management-baseline.sh
sh scripts/test-high-assurance-security-baseline.sh
sh scripts/test-zero-trust-runtime-authority-baseline.sh
Source Records