3 ms·
Thanks! And good question, lets unpack a few things: - OpenZiti is opinionated on trust and thinks PKI is the best way to ensure every element in the private ov
by PLG88 2y ago
Thanks! And good question, lets unpack a few things:
- OpenZiti is opinionated on trust and thinks PKI is the best way to ensure every element in the private overlay network uses secure identity-based authentication and authorization. Thus OpenZiti has a built-in CA/PKI, with third-party CA support (RFC 7030). In any scenario, all identities verify the JWT, verify the controller, request CSR and enroll via CSR if all validated. Nothing can access the private network without secure identity-based authentication and authorization.
- Due to every element having an identity, across the overlay we route according to the identity. This effectively provides you with a private DNS which does not need to comply to top-level domains.
- When we define a service to connect from endpoint (ingress) to endpoint (egress), it gets stitched together across the OpenZiti fabric, specifically the edge routers, which act as a smart routing data plane. The endpoints at source/destination are making outbound connections to the routers which is providing the 'turn server' functionality. These can be hosted anywhere, whether in your private network or across the WAN (or internet).
So, the answer is closer to your second suggestion but with some nuances. Net result, no need for VPNs, complex FW rules or inbound FW ports, public DNS, bastions, NAC, L4 load balancers, and more.