5 ms·
It has nothing to do with a third party. You can do everything yourself if you'd like. Zero Trust just means: 1. Server is authenticated. Client is authenticat
by staticassertion 5y ago
It has nothing to do with a third party. You can do everything yourself if you'd like. Zero Trust just means:
1. Server is authenticated. Client is authenticated.
2. Client has to pass some kind of attestation / meet policy requirements of the service.
3. Actions are auditable.
What would you call it? Zero Trust seems fine to me.
- netr0ute 5y agoThose three steps are literally AAA and nothing else, so "zero trust" is sounding like yet another marketing buzzword.
- unethical_ban 5y agoMany, many resources on a traditional internal network do NOT have unified AAA. It's about more than slapping a login page on something, it's about making sure that every gateway to an application or data has a nigh unbreakable access control (think AWS IAM when properly configured). Almost no large scale business network in the world can say this. And with IOT, it's even harder.
- staticassertion 5y agoI'm oversimplifying. The interesting bits are in (2), which typically takes contextual information into account with regards to policy. But sure, AAA is an extremely broad term that absolutely could encompass ZT. Just like SOA encompasses Microservices.