Conversation
Harden Trust Bundle retrieval (origin rule for discovered bundle URIs, mandatory trustDomain check, CA-only anchor entries, refresh jitter and limits, sequence-regression logging, integrity of cached trust material), tighten the TLS baseline (no early data, TLS 1.2 fallback off by default, protected proxy-to-backend connection, authenticated time source, clock-skew limit), and limit presented chains to six certificates. Add identity-failure handling for deployed workloads, a security event list, and threat rows for replay, local tampering, trust endpoint denial of service, and see-thru gateways. Threat tables now cross-reference their rules instead of restating them. Also align the 403 prose with the not-authorized problem type and scope the digest 404 descriptions to the caller. This addresses #226. Findings outside MIAF are tracked separately. Signed-off-by: Matthias Lechner <matlec.public@gmail.com>
phil-abb
approved these changes
Oct 1, 2026
ajcraig
approved these changes
Oct 1, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR addresses the MIAF findings of the security review in #226.
Main changes:
trustBundleUrifrom the discovery document on another origin. ThetrustDomaincheck becomes a MUST. Bundle entries whose certificate is not a CA certificate are ignored. Clients randomize and limit the refresh interval, signal an old bundle, and log aspiffe_sequenceregression. The SPIFFE ordering rules stay unchanged, so existing SPIFFE deployments stay conformant./margo/path that no identity profile defines, and the framework states what MIAF does not take over from SPIFFE. An identity failure stops Management Interface calls but does not stop deployed workloads.not-authorizedproblem type, and the digest404descriptions are scoped to the calling client.Some findings belong to the MIAF SUPs and are in margo/specification-enhancements#84 and margo/specification-enhancements#95. The findings outside MIAF stay open in #226.
Issues Addressed
Change Type
Please select the relevant options:
Checklist