Record certificate continuity, existing-user validation, and full-mix target telemetry while preserving the documented evidence limits.
Decouple user provisioning from HTTPS identity storage while retaining compatible v1 user records and migrating TLS material to the credential-free v2 format. Add focused security regression coverage and update operator documentation.