4 ms·
Based on the article, the private keys for peer enrollment signing are generated locally on each Tailscale client and aren't distributed at all. I don't see why
by dvzk 4y ago
Based on the article, the private keys for peer enrollment signing are generated locally on each Tailscale client and aren't distributed at all. I don't see why you couldn't write a custom client that approves or denies new peers based on your own criteria. Some of the internal Tailscale API may first need to be officially documented.