How Uber, Facebook and Netflix Do SSH
gravitational.com
gravitational.com
The only remotely meaningful part is the plug for their product at the end.
I don't remember the exact number, but their smallest licence was supposedly over 40k€.
Maybe it was a misunderstanding but I didn't pursue it at that point. Even a tenth of that price would've been a hard sale.
That's not so different from BeyondCorp and Uber's model.
Alternatively, some kind of OpenID Connect init (oidcinit) to get a JWT and then a PAM module like the kerberos one (which also checks the JWT's Key Id for revocation on authentication)
users with totp tokens can kinit using their password+totp in the password field. better still, if you use PAM for all your services, you you can define hbac rules allowing users access to specific services on specific hosts.
the caveat is that the freeipa servers must be available to provide authorization even once the ticket is issued. with x509, the authenticating host doesn't need to rely on a server for anything but CRL checks
Zero trust model is often explained incorrectly and misunderstood as allowing internal services like OpenSSH directly exposed to public all the time. In actual, it also works similar to VPN having perimeter security but in a dynamic way. There should be a proxy separate from actual service for authentication and only authentication service is exposed to public traffic all time, while internal resource only accepts inbound traffic from IP address of user who has authenticated successfully and this is orchestrated in real-time by the authentication service. The traffic from same user to internal service is also denied the moment they log off, think of it like a dynamic iptables system. Another emphasis of zero trust model is to authenticate requests even when it's coming from the same internal subnet. Too many articles are misleading people that zero trust model is to take away perimeter security entirely.
Note: Exposing any internal services like SSH, message queues or databases directly to public is not the right approach, because they can get compromised when there's any RCE vulnerability.
Is that true of _every_ system? I can imagine they have at least some systems which must be isolated, like BMS or other systems which typically run a decade of more behind in technology, unless they build their own, but then what about sites where they rent from WeWork competitors?