New CS proposal: Cross-organization mTLS #1492
Labels
ACK_OBTAINED
Issue acknowledged from core team so work can be done to fix it.
NEW_CS
Issue about the creation of a new cheat sheet.
What is the proposed Cheat Sheet about?
There is currently zero standards around how organizations can setup mTLS between them. In the absence of any recommendations, people will just make up whatever rules appeal to them. These rules basically make zero sense if you understand TLS at any level, but on the plus side they also carry the risk of hard downtime if a mistake is made or if someone is on vacation.
What security issues are commonly encountered related to this area?
What is the objective of the Cheat Sheet?
Fundamentally, I want a standard I can point to such that it mitigates the following risks:
What other resources exist in this area?
The quality of documents around mTLS is shockingly poor. Most tutorials on the subject recommend hard-coding credentials.
Other documents are basically sales pitches for low-quality vendor solutions which work only inside a walled garden.
The text was updated successfully, but these errors were encountered: