Skip to content

docs: address the MIAF pre-draft security review - #227

Open
matlec wants to merge 1 commit into
pre-draftfrom
fix/miaf-security-review-226
Open

matlec wants to merge 1 commit into
pre-draftfrom
fix/miaf-security-review-226

Conversation

@matlec

@matlec matlec commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Description

This PR addresses the MIAF findings of the security review in #226.

Main changes:

  • Trust Bundle retrieval: a client that trusts public CAs rejects a trustBundleUri from the discovery document on another origin. The trustDomain check becomes a MUST. Bundle entries whose certificate is not a CA certificate are ignored. Clients randomize and limit the refresh interval, signal an old bundle, and log a spiffe_sequence regression. The SPIFFE ordering rules stay unchanged, so existing SPIFFE deployments stay conformant.
  • TLS baseline: no TLS 1.3 early data, the TLS 1.2 fallback is off by default, the connection from a TLS-offloading proxy to the backend must be protected, and clients use an authenticated time source where one is available.
  • SVIDs: a verifier rejects a presented chain of more than six certificates and RSA keys with an exponent below 65537.
  • Framework and WFM profile: the MIS does not issue a /margo/ path that no identity profile defines, and the framework states what MIAF does not take over from SPIFFE. An identity failure stops Management Interface calls but does not stop deployed workloads.
  • Security considerations: a minimal list of security events, new threat rows (replay, local tampering, trust endpoint denial of service, see-thru gateways), and threat tables that cross-reference their rules instead of restating them.
  • Management Interface: the 403 prose names the registered not-authorized problem type, and the digest 404 descriptions are scoped to the calling client.

Some findings belong to the MIAF SUPs and are in margo/specification-enhancements#84 and margo/specification-enhancements#95. The findings outside MIAF stay open in #226.

Issues Addressed

Change Type

Please select the relevant options:

  • Fix (change that resolves an issue)
  • New enhancement (change that adds specification content)
  • Content edits (change that edits existing content)

Checklist

  • I have read the CONTRIBUTING document.
  • My changes adhere to the established patterns, and best practices.

Harden Trust Bundle retrieval (origin rule for discovered bundle URIs,
mandatory trustDomain check, CA-only anchor entries, refresh jitter and
limits, sequence-regression logging, integrity of cached trust
material), tighten the TLS baseline (no early data, TLS 1.2 fallback
off by default, protected proxy-to-backend connection, authenticated
time source, clock-skew limit), and limit presented chains to six
certificates. Add identity-failure handling for deployed workloads, a
security event list, and threat rows for replay, local tampering,
trust endpoint denial of service, and see-thru gateways. Threat tables
now cross-reference their rules instead of restating them.

Also align the 403 prose with the not-authorized problem type and scope
the digest 404 descriptions to the caller.

This addresses #226. Findings outside MIAF are tracked separately.

Signed-off-by: Matthias Lechner <matlec.public@gmail.com>
@matlec
matlec requested a review from a team as a code owner September 28, 2026 15:08

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants