Skip to content

feat: qualify CA-issued TLS and plan SCAP scanning - #6

Merged
joey-huckabee merged 6 commits into
mainfrom
feature/ca-tls-rehearsal
Sep 7, 2026
Merged

joey-huckabee merged 6 commits into
mainfrom
feature/ca-tls-rehearsal

Conversation

@joey-huckabee

Copy link
Copy Markdown
Contributor

Adds connected and disconnected CA-issued TLS qualification to both native architecture jobs, fixes loopback TLS health behavior for certificate chains, and documents the offline operator rehearsal. Also adds the staged, least-privilege oscap-chroot design and additional cybersecurity gates to the first-release roadmap. Local pre-commit validation passes; native Linux CI is the authoritative evidence for the complete rehearsal and Unix permission case.

@joey-huckabee
joey-huckabee merged commit 711cbe4 into main Sep 7, 2026
6 checks passed
@joey-huckabee
joey-huckabee deleted the feature/ca-tls-rehearsal branch September 7, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant