CLI command
skarbiec recovery-drill
Prove that exactly one expected recovery identity in an isolated keyring can decrypt a deterministic live canary.
Invocation#
skarbiec recovery-drill <recipient-uid|recovery>Purpose#
Prove that exactly one expected recovery identity in an isolated keyring can decrypt a deterministic live canary.
Required inputs and options#
- Requires a registered recovery recipient uid or the literal recovery. GNUPGHOME must point to an isolated keyring containing only that expected vault opener.
Output and state effects#
- Decrypts and discards the lowest live item as a canary, appends pass/fail evidence, and prints status, recipient, fingerprint, canary_item, and isolated_keyring.
Refusals#
- Refuses a missing secret half, a non-isolated keyring with another vault opener, an unknown recipient, or an empty vault.