3 ms·
If you require client certificates then you don't need to worry about non-insider attacks on anything other than your TLS library and your client cert bootstrap
by robryk 4y ago
If you require client certificates then you don't need to worry about non-insider attacks on anything other than your TLS library and your client cert bootstrap procedure.
- hotpotamus 4y agoI didn't even think of that as a possibility, but it's a good suggestion and something that's within the realm of feasible (though far from trivial) for us. Thank you.
- robryk 4y agoTBF putting a reverse proxy that does authn and rejects requests that do not authn correctly in front of everything (except for the login pages) is nearly as good: the exposed area is then login page, reverse proxy, and the authn login in the reverse proxy. That might be vastly simpler to implement.