certificates
certificates copied to clipboard
Add a policy type for permanent IDs
Right now you have to use the DNS policy type if you want an allow/deny policy for YubiKey serial numbers or other hardware identifiers. It just happens to be DNS because DNS is the default policy type for anything that isn't ip, email, or CN.
It would be nice to have a policy type dedicated to permanent IDs.