Skip to content

MIAF pre-draft security review #226

Description

@Zangarus

Bug description

Findings are all related to the Margo (pre-draft) specification, not to any implementation / executable code. Therefore after discussions with the TWG Chairs, the security policy does not apply and there is no need to report the findings as a vulnerability according to the policy.

Findings come from a review of pre-draft, re-verified at f6c2305a28 (2026‑08‑27) after #194 and #25 merged and after #205 (RFC 9457 problem details) and #211 were opened.

ID Severity Title
01 High Require an explicit origin allowlist for trustBundleUri
02 High Restore rollback detection and add a staleness signal after spiffe_sequence removal
03 High No replay protection: constrain TLS 1.3 early data on the Management Interface
04 High Require integrity protection of cached trust material at rest
05 High Desired state cannot pin a workload artifact by immutable digest
06 Medium Define what a device MUST refuse in a Compose workload, and pin the Compose Specification version
07 High MIAF sets no floor for key protection or SVID lifetime
08 Medium Secure the proxy-to-backend hop in TLS-offload topologies, per RFC 9440 Section 4
09 Medium Add verification guardrails for PKCS#1 v1.5 signatures and ECDSA nonce generation
10 Medium Constrain Trust Bundle anchor entries: x5c count, JWK binding, and CA-ness
11 Medium Require an authenticated time source or an anti-rollback store for certificate validation
12 Medium Define a minimal MIAF audit event set
13 Medium State that identity failure halts the management plane but does not stop running workloads
14 Medium Bound certificate chain depth and presented-chain size
15 Medium State the security cost of a shared wfm-id, and require per-instance key pairs
16 Medium Define testable output constraints for MIS conformance
17 Medium Bound Compose Archive entry count, uncompressed size and compression ratio
18 Medium revision comparison is ambiguous: the tag mapping is lossy and SemVer precedence ignores build metadata
19 Medium DeviceId permits . and .. path segments
20 Low Bundle endpoint resilience: pin rotation, refresh jitter and bound, rate limiting
21 Low TLS 1.2 fallback opt-in, and an unregistered problem type in the 403 example
22 Low Enforce the /margo/ namespace at issuance, and a question about the removed body type discriminator
23 Low State a hybrid key-exchange position and the chain-size implications of PQ signatures
24 Informational Add a threat row for a compromised or malicious see-thru gateway
25 Low Endpoint 404 wording contradicts the caller-scoping rule, and two navigation manifests are wrong
26 Strategic Authenticated supply chain: signed desired state and attestation-backed issuance
27 Low Identity concepts pages: late-binding cost, TLS-offload hop owner, bootstrap authentication in the diagram
28 Low The inspection exemption asks operators to deviate from their own IEC 62443 zone-and-conduit policy

Detailed explanations to each finding are provided in the attached filed 00-consolidated-issue.md.

Proposed fix

Proposed solutions are incorporated in the explanation file 00-consolidated-issue.md.

Anything else (optional)

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions