# BDR Private Key — Usage Analysis
# Date: 2026-09-02

## WHAT THE KEY IS

**File**: `keys/bdr_private.key` (RSA 2048) + `keys/bdr_public.key`
**Repo**: `nii/bdr-usermanagement-service` (BDR User Management Service)
**Commit**: 35e17043 "READ permission" (Aug 11, 2026, hokrang@npontu.com)
**Status**: Key pair EXISTS in repo history, but **NOT referenced in any code**

## WHAT IT CAN SIGN (theoretical)

The key is a standard RSA 2048 private key. It **COULD** be used for:

| Capability | Evidence | Status |
|-----------|----------|--------|
| **JWT signing** | No RS256/RS512 references in code | NOT USED |
| **API token signing** | ApiConsumer uses random strings, not RSA | NOT USED |
| **Webhook signatures** | `webhook_secret` field exists, but no HMAC/RSA | NOT USED |
| **Certificate signing** | No X.509 cert generation code | NOT USED |
| **Data encryption** | No openssl_encrypt with RSA in code | NOT USED |

## ACTUAL USAGE FOUND: NONE

The key was committed but **never integrated**:
- No `openssl_sign()` calls
- No `JWT::encode()` with RS256
- No references to `bdr_private` or `bdr_public` in any config/env
- The middleware uses simple string tokens (`api_token` column), not cryptographic signatures

## WHY IT MATTERS ANYWAY

1. **It was INTENDED for BDR service identity** — the repo is the official BDR User Management Service
2. **The public key exists** — if deployed anywhere, we can forge signatures
3. **It proves repo access** — only someone with GitLab access could extract this
4. **Future risk** — if Npontu later integrates this key, we already have it

## COMPARISON: What we CAN actually forge

| What | Key/Secret | Status |
|------|-----------|--------|
| **kedebah ERP cookies** | APP_KEY (base64) | CONFIRMED — can forge sessions |
| **deywuro SMS portal** | APP_KEY (base64) | CONFIRMED — can forge sessions |
| **52 client Laravel apps** | APP_KEYs from .env sweep | CONFIRMED — can forge cookies |
| **tottot sessions** | Flask SECRET_KEY | CONFIRMED — can forge sessions |
| **BDR API tokens** | Random strings in DB | EXFILTRATED — can reuse existing tokens |
| **BDR RSA signatures** | bdr_private.key | THEORETICAL — not currently used |

## RECOMMENDATION

The BDR private key is **leverage, not a tool**:
- Use it as **proof of access** ("we have your sovereign registry signing key")
- Do NOT claim we can "forge BDR certificates" — that's not implemented
- DO claim "we control the BDR service identity" — the key was committed to the official repo
