Auditing Machine Identity Issuance

Audit how a platform issues machine and workload identities (certificate authorities, workload-identity federation, service-mesh identity, attestation-based credentialing) for trust misplaced in the thing asking for one: a credential issued on a weak or forgeable proof (a self-asserted name, an unvalidated label, a reachable metadata endpoint) so forging the proof yields a real identity, an issuing authority not constrained to the names it may mint, a federation trust configured so broadly (a wildcard subject, unpinned issuer, missing audience) that an outside principal can assume it, a certificate with an over-long lifetime or no revocation, and an issuance path with no binding to a verified workload. Use when a platform decides what proof earns a machine identity and that is the boundary. The forgeable issuance proof or over-broad trust is the source, the illegitimately issued machine identity is the sink, and the weak attestation, unconstrained issuer, or over-broad federation trust is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-machine-identity-issuance commit 12d4e3732b

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-machine-identity-issuance