Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
{ "binaries": [ { "binary_name": "golang-github-lxc-lxd-dev", "binary_version": "2.0.11-0ubuntu1~16.04.4+esm1" }, { "binary_name": "lxc2", "binary_version": "2.0.11-0ubuntu1~16.04.4+esm1" }, { "binary_name": "lxd", "binary_version": "2.0.11-0ubuntu1~16.04.4+esm1" }, { "binary_name": "lxd-client", "binary_version": "2.0.11-0ubuntu1~16.04.4+esm1" }, { "binary_name": "lxd-tools", "binary_version": "2.0.11-0ubuntu1~16.04.4+esm1" } ] }