3 ms·
I believe in this case he's talking about MTLS: > OASA also protects these hops by issuing client certificates with 10-minute expirations after first verifying
by bb611 7y ago
I believe in this case he's talking about MTLS:
> OASA also protects these hops by issuing client certificates with 10-minute expirations after first verifying your identity through our single sign-on provider, and then also verifying you are on a pre-enrolled (and approved) trusted company device.
- sullivanmatt 7y agoBasically. Since we are focusing on SSH in this post (and keep in mind that SSH is its own protocol, separate from TLS), it's conceptually the same: client has a certificate and a key, signed by a trusted certificate authority, and the client is also in possession of the server certificate authority. So then you have a bi-directional trust established. The certificates are short-lived, and issued after a successful authentication + dial request to the OASA service.