4 ms·
Isn't this an idp? I'm totally unclear how this is differentiated from an idp that also requires a hardware key.
by beardedwizard 2y ago
Isn't this an idp? I'm totally unclear how this is differentiated from an idp that also requires a hardware key.
- elevation 2y agoIt _has_ an IdP, but you have to be authenticated at a lower layer in the stack before you can talk to it. Think Tailscale+Let's Encrypt+Okta but all in a single package.
- kchr 2y agoI guess it could be categorised as a PAM (privileged access management) solution with a built-in IdP?
- mrmetanoia 2y agoI was about to say this sounds like our on prem PAM setup which is integrated with our idp - or some mixture of things folks are asking about. Seems like this is something largely solved regardless of how it's being done, but maybe we're all missing something. Or maybe his implementation is just that slick.
- elevation 2y agoDoes your PAM include a data loss prevention feature?
- mrmetanoia 2y agoYes
- beardedwizard 2y agoBut that's just certificate auth, which happens during session establishment and before data transmission isn't it? So isn't it an idp with cert auth as the primary first factor?
- klaushardt 2y agoSo for example Shibboleth with privacyIDEA and enabled webAuthn and 2FA for AnyConnect or some other VPN?
- beardedwizard 2y agoThis is what I was thinking