====== Sensitive Configuration Value ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go up to Terms and Definitions]] ===== Discussion ===== A Sensitive Configuration Value is a [[dido:99_annexes:annex-b-terms-and-definitions:c:configuration_value|Configuration Value]] requiring protection against unauthorised disclosure, alteration, substitution, destruction, or use. Sensitive Configuration Values include passwords, authentication tokens, private keys, shared secrets, personal information, proprietary information, protected network information, security settings, and values whose alteration compromises the operation or protection of a [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Node]]. Sensitivity depends upon the value’s meaning, purpose, classification, operational context, applicable [[dido:99_annexes:annex-b-terms-and-definitions:p:policy|Policy]], and consequences of compromise. A value therefore remains sensitive even when its textual or numeric representation appears innocuous. Protection addresses both [[dido:99_annexes:annex-b-terms-and-definitions:c:confidentiality|Confidentiality]] and [[dido:99_annexes:annex-b-terms-and-definitions:i:integrity|Integrity]]. Some values, including public certificates and security-policy settings, require integrity protection without secrecy. Other values, including private keys and passwords, require both confidentiality and integrity protection. ===== Definition ===== //Configuration Value requiring protection against unauthorised disclosure, alteration, substitution, destruction, or use// ===== Source ===== DIDO Solutions project definition. ===== Note ===== A Sensitive Configuration Value retains its classification and handling requirements throughout acquisition, [[dido:99_annexes:annex-b-terms-and-definitions:c:configuration_resolution|Configuration Resolution]], [[dido:99_annexes:annex-b-terms-and-definitions:c:configuration_application|Configuration Application]], use, rotation, revocation, retention, and disposal. A protected reference, [[dido:99_annexes:annex-b-terms-and-definitions:i:identifier|Identifier]], digest, token, or redacted representation supports identification and Traceability without exposing the protected value. A [[dido:99_annexes:annex-b-terms-and-definitions:c:configuration_record|Configuration Record]] identifies the applicable protection method and protected reference rather than reproducing a confidential Sensitive Configuration Value. A [[dido:99_annexes:annex-b-terms-and-definitions:c:credential|Credential]] or item of [[dido:99_annexes:annex-b-terms-and-definitions:c:cryptographic_material|Cryptographic Material]] constitutes a Sensitive Configuration Value when assigned to a Configuration Parameter. ===== Example ===== A secret-store reference assigned to the parameter `clientPrivateKey` identifies a Sensitive Configuration Value without exposing the private key in the Node Configuration or Configuration Record. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.