SOPS currently uses HTTP Client to connect with Vault, with support for TLS.
In case of Certificate Breach and Revocation, the old certificate could still be validated by the Vault HTTP Client.
In order to prevent exposure, can we add CRL support to SOPS?
We are happy to work on a PR for this
SOPS currently uses HTTP Client to connect with Vault, with support for TLS.
In case of Certificate Breach and Revocation, the old certificate could still be validated by the Vault HTTP Client.
In order to prevent exposure, can we add CRL support to SOPS?
We are happy to work on a PR for this