And if it doesn’t, does the enrollment secret prov...
# kolide
g
And if it doesn’t, does the enrollment secret provide enough security to connect fleet and hosts on an untrusted network?
z
There is no support currently. You could front the Fleet server with a proxy that does mTLS.
I'd also be happy to do a consulting engagement to add this.
Most folks consider enroll secret + node keys to be sufficient.
1
s
If anything, I’m very interested if any rogue hosts enroll in my Fleet
s
Im curious: what would a rogue osquery host do when attached to Fleet?
1
g
Pretend to be a host that they’re not
but yea I don’t think it’s the biggest worry in the world, was just curious
s
^^^That makes sense. Take offline the legit host and stand up a bad one that shows nothing is wrong