Certificate Lifecycle Service · View 21 of 21 · Assurance
The refusal
- Messages 9 to 12 are the whole point: a workload in one namespace asking for another namespace's identity is denied on policy, not on a name check at the CA.
- Message 12 matters as much as message 11. A denial that is not recorded cannot be investigated, and the denial rate is a standing security signal.
Decisions
- Identity is derived from an attested platform credential and never from a self-asserted subject in the CSR.
- Identity is encoded in a structured SAN — trust domain, namespace, service — so that authorization policy can be written against a parseable identity rather than a string convention in a common name.
- Changing the rule is itself a two-person operation: an administrator relaxing a constraint needs a second approver, and the change is audited immutably.
Assumption
- Customer domain control is re-proved on a declared cadence rather than trusted indefinitely, which is the equivalent control on the public-trust side.