Mikko Ylinen

Results 291 comments of Mikko Ylinen

I'm noticing this behavior too and I find it wrong. @lujinda @cardyok maybe ping on `#sig-node` Slack to get this triaged and/or commented?

TODO: @hj-johannes-lee is still checking whether the `vfio-pci.ids=` cmdline settings can an alternative to `Unconfined`.

> Unfortunately `vfio-pci.ids=` way does not alternate apparmor related matters. There is no difference between having it or not. I took a closer look. `vfio-pci.ids=` can help here but we...

A similar effort is already ongoing on [SLSA side](https://github.com/slsa-framework/slsa/issues/975). > We could perhaps refer to this in other documentation that is broad Something along these lines was planned to be...

> What should I do to solve this problem? The problem is that AS is built with `all-verifiers` feature by default. The fix is to built with the desired verifiers.

My earlier comment in the original PR was that my preference is to not expose "ITA" as a token type to the user and that seems to be in this...

> The modification is the configuration name in the config file, from `trusted_certs_paths` to `trusted_jwk_sets`. > > Another option is `trusted_certs_paths`. It's for trusted root certs to verify the `jwk`/`x5c`...

Would it be OK to aim fixing #519 with PR too?