Independent offsite recovery of the replacement Nitro diagnostic
On 2026-09-09, Hetzner fetched the four named public artifacts through its direct SSH tunnel to the AWS origin, verified their content-addressed SHA256 filenames, and saved/read back their exact bytes in a separate retained diagnostic directory. The producer's epoch key was never fetched or copied.
Using freshly installed client and Linux native wheels 0.2.0a2, an offline
unshare --net process authenticated the archived Nitro evidence to diagnostic
PCR0 595729e56f1bdcb58af070df3d71371ff33f07df48abb8c1c4472e83e1d12a6bb011addbf0db702597a8dc14f35a8b91,
solved the genuine eight-iteration puzzle with new checkpoints, and verified the
recovered key commitment. The recovered plaintext was checked as canonical CBOR
with version 3, exact epoch and software-version fields, and no trailing bytes.
The recorded response was HTTP 200 with 559 body bytes. Its independently recovered
body SHA256 was
ff67a9d764d6a2367a187734e697f6a53217db9a21c101d410a113ca871a299d,
exactly matching the producer-side observed response. Full CBOR plaintext SHA256:
1558b25ff1f0bfbbfa68b5b17f75c5fec9be89299f84d754000331e6bbbe5d15.
The scoped relay-archive-v2 profile, running as relay-fleet-v2, also verified
all four exact artifacts in the AWS S3 archive under artifacts/. They already
existed because the continuous mirror had copied them; the explicit verification
was idempotent and read back every byte. No object, key, file or retention policy
was deleted or changed. The live fleet's package versions and PCR pin were not
changed by this proof.
Public fetch, S3 readback and recovery summaries are retained here. Ciphertext,
freshly recovered diagnostic key, checkpoints and decrypted CBOR remain on Hetzner
under /var/lib/attested-relay-fleet-v2/diagnostic-a2-20260909/. This short diagnostic
proves independent interoperability and authentication, not production delay.