An SVID is a short-lived X.509 certificate — and it is always about to expire
X.509-SVID TTL 1h
SAN: spiffe://acme/svc-a
issuer: static CA
expiring — renew against the CA, again
Renew it every hour against a central CA. Miss one renewal and the workload drops offline.
The same X.509-SVID, issued and verified against a provenance log
X.509-SVID valid
SAN: spiffe://acme/svc-a
trust root: provenance log
signed & replayable
A verifier checks it against the plog-derived trust bundle → ✓ verified, no CA online required
It is a standard X.509-SVID every SPIFFE-aware tool understands — the difference is where the trust comes from.