Security hardening (krl-client)
Completes the krl-client pre-release hardening from the v3.4.0 review (all three findings now resolved). Monorepo patch bump 3.4.1 → 3.4.2.
Fix
- Anti-rollback now trusts the signed KRL version, not an unsigned field ([TASK-175]) — low. Rollback protection previously compared the
krl_numberfrom the unsigned JSON payload, so a compromised server could replay an old but validly-CA-signed KRL with an inflated number to silently un-revoke keys. The client now reads the monotonic version number from the CA-signed OpenSSH KRL header (thekrl_versionfield inside the bare KRL bytes), which is covered by the detached signature oversha256(krl)and therefore cannot be forged. The unsignedkrl_numberfield is dropped from the protocol entirely (backend payload + client), and a replayed old-but-signed KRL is now rejected with exit8regardless of any inflated JSON value.
Ships with a regression test (inflated unsigned number over an older signed header → rejected), full KRL-header-guard coverage, and regenerated golden vectors validated against real ssh-keygen -Q. decision-015, doc-007, and the README are updated. Release artifacts (static linux/amd64 binary, SHA-256 checksums, keyless cosign signature, SPDX SBOM) and their verification steps are unchanged from v3.4.0.
Full Changelog: v3.4.1...v3.4.2