7 ms·
It would dramatically limit your attack surface to those who could gain access to your VPN. I prefer requiring TLS mutual authentication with a corporate PKI a
by jodoherty 5y ago
It would dramatically limit your attack surface to those who could gain access to your VPN.
I prefer requiring TLS mutual authentication with a corporate PKI and issuing employees client certificates.
Doing both wouldn't be a bad idea either.
- relaunched 5y agoThe number of software products, SaaS and on-prem, that don't support mutual tls is a disgrace.
- tfigment 5y agoI frequently do mTLS with a reverse proxy (httpd, nginx, caddy, ...). Not perfect but you can tighten the connection security a lot without touching the other service. But by outsourcing it you lose some control.
- PLG88 5y agoWe put all our DevOps tools behind Open Ziti (ziti.dev) which ensures we do not need any public IPs (unlike a VPN or bastion) while giving granular access control for only trusted users.