Spaces:
Running
Running
|
Download ayllu/keys/README.md from SZLHOLDINGS/a11oy: direct link, hf CLI and curl.
- Browser
- Download file 1.5 kB
-
https://huggingface.co/spaces/SZLHOLDINGS/a11oy/resolve/c18b71e1c58e2df66b991e889b0149a8d85f4699/ayllu/keys/README.md
- Command line
-
hf download hf://spaces/SZLHOLDINGS/a11oy@c18b71e1c58e2df66b991e889b0149a8d85f4699/ayllu/keys/README.md
-
curl -L -o README.md https://huggingface.co/spaces/SZLHOLDINGS/a11oy/resolve/c18b71e1c58e2df66b991e889b0149a8d85f4699/ayllu/keys/README.md
1.5 kB
AYLLU council verifying keys
council-runtime-2026-07-21.pub (ECDSA P-256)
The public key that verifies the DSSE council receipts emitted by the live
a11oy Space (POST /api/a11oy/v1/ayllu/council), pinned here so the wall
(/api/ayllu/wall) and the offline verifier
(scripts/verify_ayllu_council_receipt.py) can fail closed against it.
Provenance (stated honestly, 2026-07-21):
- The live Space signs with the
SZL_COSIGN_PRIVATE_KEY_PEMruntime secret. Its envelopes carry the keyid labelszlholdings-cosign, but the signatures do NOT verify against the published org key atszl-holdings/.github/cosign.pub— the Space's own public verifier (/api/a11oy/v1/verify/receipt) reports the sameMISMATCH. - This public key was therefore recovered from two independent live council signatures (ECDSA public-key recovery over the DSSE PAE bytes; the two candidate sets intersect in exactly ONE point) and cross-checked against both receipts. Recovery uses only public signature material.
- Owner action pending: reconcile the Space's signing secret with the
published
cosign.pub(or rotate/republish), then re-pin here. Until then, verification against this pin proves "signed by the a11oy runtime key and unaltered" — it does not prove custody of the published org key.
Fingerprint (sha256 of the PEM bytes as committed):
see sha256sum council-runtime-2026-07-21.pub, also surfaced live in the
wall's keyHonesty.fingerprintSha256.