Skip to content

standard

X.509

Certificate format into which the CA binds the forged Domain Controller identity data returned by the attacker-controlled endpoint.

Known aliases

  • X509
  • X.509 certificate
  • X.509 certificates

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Kubelet takes over delivering an X.509 identity to each pod

KEP-4317 pairs a pod-scoped certificate request with a projected volume, so the kubelet provisions the key and kube-apiserver enforces node restriction. What is left for a signer to do is the CA work.

Publishers:kubernetes.dev

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence55