CLI command
skarbiec key-doctor
Determine directly from the vault and keyring whether this host has a key that can open a deterministic live canary.
Invocation#
skarbiec key-doctorPurpose#
Determine directly from the vault and keyring whether this host has a key that can open a deterministic live canary.
Required inputs and options#
- No positional input. The configured vault and current GPG keyring are inspected directly.
Output and state effects#
- Prints vault, owner, readable/empty/unreadable status, canary id, possible openers, recipient fingerprints/keygrips, backup file names, and a remedy. Plaintext is discarded.
Refusals#
- An absent secret half or failed canary open is reported as unreadable with a restore-and-rotate remedy; it is never reported as a missing item.