Marcos Yacob

Results 39 issues of Marcos Yacob

Force the rotation of Server SVID when it was signed by a tainted key Depends on #3894 #3897

priority/backlog

Upstream authorities are propagating the list of tainted keys, but we need a way to taint the local authority that was signed by a downstream key that is now tainted....

priority/backlog

Remove cached JWT SVIDs that are signed by a tainted key Depends on #3901

priority/backlog

Update agent sync to rotate all cached SVIDs affected by a tainted Key Depends on #3901

priority/backlog

Add a new package to push status to SPIRE Server and keep the list of tainted keys The list of tainted keys must be kept here and propagated to Agent...

priority/backlog

SPIRE Upstream authority must obtain the list of tainted keys from NewDownstreamX509CA and GetBundle, to propagates tainted keys to SPIRE Server Depends on #3885 #3886 #3899

priority/backlog

Propagate Tainted keys when using NewDownstreamX509CA Depends on #3885

priority/backlog

Implement PushStatus RPC on Agent API Depends on #3885

priority/backlog

Add taint field to JWT and X509 parsing code Depends on #3885

priority/backlog

Sigstore was added as an extension for k8s workload attestor, and a [PR](https://github.com/spiffe/spire/pull/3504) was open with an integration test. But it is using a signed image on a user repository,...

priority/backlog