github oriolrius/pki-manager-web v3.5.0
v3.5.0 — Per-host SSH access blocks (BLK milestone)

latest releases: v3.12.3, v3.12.2, v3.12.1...
3 months ago

Per-host SSH access blocks (BLK milestone)

Monorepo version bump 3.4.2 → 3.5.0 (root/frontend/backend). This release delivers the
per-host SSH access-blocks milestone (BLK-00..BLK-13): the ability to block a specific
user/identity on a specific host by composing a per-host KRL, signed by the Host CA and
distributed via the existing encrypted per-host endpoint — without revoking the user's
certificate everywhere.

Highlights

Composed per-host KRLs

  • SshHostKrlService (TASK-180) — builds a composed per-host KRL with a global
    monotonic number
    and Host-CA signing, so each host receives exactly the revocations
    that apply to it, anti-rollback intact.
  • Serving cutover (TASK-183) — the public per-host endpoints now serve the ECIES payload
    straight from ssh_host_krls, replacing the previous composition path.
  • Freshness triggers (TASK-182) — certificate issuance and revocation automatically
    regenerate the affected per-host KRLs so distribution stays current.
  • Trust-anchor reconciliation (TASK-187) — the puller's trust anchor is reconciled to
    the Host-CA public key end-to-end, matching what signs the composed KRL.

Blocking model & API

  • SshBlockService (TASK-181) — block/unblock an identity on a host, with synchronous
    per-host KRL regeneration and full lifecycle handling.
  • ssh.block.* API (TASK-185) — block operations plus a host-access/state read model,
    exposed as tRPC + REST twins.
  • Per-host KRL state + metrics (TASK-184) — state derivation and lineage metrics for
    observability of each host's KRL.
  • Optional zero-window issuance gate (TASK-190) — a flag-gated issuance gate that closes
    the window between issuing and blocking.

Frontend

  • Host Access card, Users "blocked-on" pills, and KRL distribution columns (TASK-186) —
    surface per-host block state and distribution status directly in the UI.

Testing, docs & hardening

  • E2E block matrix (TASK-188) — composed-KRL blocking verified against real sshd and
    the real krl-client, including anti-rollback.
  • Ansible + operator docs (TASK-189) — per-host KRL option, operator guide, and a cutover
    runbook.
  • Adversarial-review fixes — closed the findings from a full-milestone-diff review
    (incl. a steady-state renewal regression in the BLK-13 gate).

Release artifacts (krl-client)

Asset Purpose
krl-client-linux-amd64 static, CGO_ENABLED=0, -trimpath linux/amd64 binary
checksums.txt SHA-256 checksum of the binary
krl-client-linux-amd64.sig keyless cosign signature
krl-client-linux-amd64.pem cosign certificate (Fulcio)
krl-client-linux-amd64.spdx.json SPDX SBOM (syft)

Full Changelog: v3.4.2...v3.5.0

Don't miss a new pki-manager-web release

NewReleases is sending notifications on new releases.