Skip to content

issuer: don't log HSM PIN on misconfiguration#8794

Merged
aarongable merged 1 commit into
mainfrom
inahga/pin
Jun 11, 2026
Merged

issuer: don't log HSM PIN on misconfiguration#8794
aarongable merged 1 commit into
mainfrom
inahga/pin

Conversation

@inahga

@inahga inahga commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

If the PKCS#11 configuration is missing a required field, we dump the parsed configuration, which could contain an HSM PIN. That PIN would then be persisted in the logs, which is most unpleasant.

@inahga inahga requested a review from a team as a code owner June 10, 2026 22:11
@inahga inahga requested a review from jsha June 10, 2026 22:12

@jsha jsha left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well spotted!

@aarongable aarongable merged commit 2c34991 into main Jun 11, 2026
41 of 46 checks passed
@aarongable aarongable deleted the inahga/pin branch June 11, 2026 05:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants