Skip to content

Cap node-auth JWT certificate chains - #5060

Open
Sinck wants to merge 1 commit into
NVIDIA:mainfrom
Sinck:node-auth-token-broker
Open

Cap node-auth JWT certificate chains#5060
Sinck wants to merge 1 commit into
NVIDIA:mainfrom
Sinck:node-auth-token-broker

Conversation

@Sinck

@Sinck Sinck commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

Follow up on review feedback from the self-signed node-auth JWT work by bounding the certificate chain carried in each token. The bound stops untrusted requests from triggering unbounded certificate processing, keeps local minters and API validation compatible, and makes an oversized local bundle diagnosable without noisy logs.

Related issues

None.

Type of Change

  • Add - New feature or capability
  • Change - Changes in existing functionality
  • Fix - Bug fixes
  • Remove - Removed features or deprecated functionality
  • Internal - Internal changes (refactoring, tests, docs, etc.)

Breaking Changes

  • This PR contains breaking changes

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed
  • No testing required (docs, internal refactor, etc.)

Additional Notes

Follow-up to #4718.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant