I'm unsure if this is an issue or a discussion item, but since the discussions feature is disabled for this repository, I'm going to post it here.
The policy file allows certificates without a Subject Alternative name extension but with an arbitrary commonName in the subject to be successfully issued. The documentation explains "This prevents malicious use while still allowing users to create certificates for themselves", however to me this looks like a needlessly dangerous configuration.
- Why should users be able to request certificates from a honeypot? Those certificates serve no purpose and just trigger false positive alerts.
- If the attacker is able to modify the altSecurityIdentities attribute of an account he can create an explicit mapping between the issued certificate and that account.