CanSignAs

Source can sign tokens/blobs as the target (JWT/SAML signing -> forge identity).

credential CREDENTIAL nature: explicit walkable weight 1 high value
Identity  ── CanSignAs ──▸  SigningKey, ServiceAccount, ApplicationIdentity, EncryptionKey

Source types

Identity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Per-cloud

cloudpermissions / triggersnote
gcp iam.serviceAccounts.signBlob iam.serviceAccounts.signJwt

Rules that emit CanSignAs 23

Issue a certificate for an arbitrary subject/SAN signed by the CA's key.
awsderived
Rewrite the CA resource policy to grant self issuance, then sign as the CA.
awsderived
Issue a SubordinateCACertificate to create a new issuer chaining to the trusted CA.
awsderived
A CloudHSM CU credential (with VPC reach) can sign with the HSM private key.
awsderived
Admin of a SIGN_VERIFY key can self-grant kms:Sign and forge signatures.
awsderived
Key Vault Administrator can sign with every signing-capable key in the vault.
azurederived
A vault self-grant equally yields sign on every signing-capable key in the vault.
azurederived
A Managed HSM local Crypto User role can sign with an HSM signing key.
azurederived
Signing with an HSM key that backs a token/cert issuer lets the caller sign as that identity.
azurederived
privateca.certificates.create + caPools.use lets a principal issue a cert signed by the CA private key.
gcpderived
Issue from a KMS-backed CA; the signature is performed by the CAS service agent, not the caller.
gcpderived
A principal that can execute as a workload SA holding certificateRequester can issue certs.
gcpderived
cloudkms.cryptoKeyVersions.useToSign on an ASYMMETRIC_SIGN key forges signatures.
gcpderived
cloudkms.cryptoKeyVersions.macSign on a MAC key forges message authentication codes.
gcpderived
A key manager that can setIamPolicy can self-grant and then sign.
gcpderived
awsexplicit
awsexplicit
azureexplicit
move · open · esc close