JWT vs. mTLS for service-to-service authentication

  Рет қаралды 1,977

solo.io

solo.io

Күн бұрын

In this Hoot, we'll look at JWT and mTLS for service-to-service authentication. The two approaches look similar, but implementing them is not straightforward. If we want to implement mTLS for service-to-service authentication, we have to solve the problems around certificate management. Ideally, we want short-lived certificates, which involve frequently rotating certificates across all deployments, and that alone makes implementing it a daunting task.
This might make JWT look like a better option and easier to implement. We've been hearing about centralizing functionality into API gateways, so individual services don't have to worry about it. When thinking about implementing JWTs for service-to-service authentication, we're undoing this centralization and moving functionality back into services. It's clear that JWT has its own problems, and it's not a good fit for service-to-service authentication, especially when we know better options are available.
Many enterprises are now considering service meshes for securing service communication. Istio service mesh is stable, mature, and available and implements mTLS for service authentication.
Join Christian Posta and Peter Jausovec in this live stream, where they'll look at the different scenarios and issues with using JWT in service authentication and show how Istio with mTLS is a better option for many enterprises.

Пікірлер: 3
@learncloudnative
@learncloudnative 11 ай бұрын
Thanks everyone for joining! Check out the demos here: github.com/peterj/jwts-for-services Feel free to reach out if you have any more questions!
@HarisSiddiqui-p2g
@HarisSiddiqui-p2g 6 ай бұрын
Does Istio not support JWT authentication as well?
@learncloudnative
@learncloudnative 6 ай бұрын
Istio supports JWT for user authentication. In this stream we talked about using JWT vs. mTLS for service to service authentication.
What Is Mutual TLS (mTLS), Why Do We Need It, And How Do We Get It?
19:05
Auth Patterns: What to Use and When
35:44
Istio
Рет қаралды 2,1 М.
ДЕНЬ УЧИТЕЛЯ В ШКОЛЕ
01:00
SIDELNIKOVVV
Рет қаралды 3,5 МЛН
She's very CREATIVE💡💦 #camping #survival #bushcraft #outdoors #lifehack
00:26
Стойкость Фёдора поразила всех!
00:58
МИНУС БАЛЛ
Рет қаралды 6 МЛН
Man Mocks Wife's Exercise Routine, Faces Embarrassment at Work #shorts
00:32
Fabiosa Best Lifehacks
Рет қаралды 6 МЛН
mTLS: When Certificate Authentication is Done Wrong
22:14
Black Hat
Рет қаралды 1,6 М.
mTLS with NGINX
31:01
NGINX
Рет қаралды 16 М.
Security with Istio: Using Authorization Policies
12:11
Lukonde Mwila
Рет қаралды 4,3 М.
Microservice Authentication and Authorization | Nic Jackson
1:05:43
DevOps Conference
Рет қаралды 78 М.
Istio & Service Mesh - simply explained in 15 mins
16:09
TechWorld with Nana
Рет қаралды 663 М.
Diving into BGP with Cilium
1:18:39
solo.io
Рет қаралды 850
ДЕНЬ УЧИТЕЛЯ В ШКОЛЕ
01:00
SIDELNIKOVVV
Рет қаралды 3,5 МЛН