Hacker News new | ask | show | jobs
by tremon 12 hours ago
A short-lived credential would reduce the risk that the key is still valid when an agent gains access

How does that work? If the agent is reading the credential from the live configuration, how short does the lifespan of a key need to be to prevent it from being used by an unauthorized process?

1 comments

Long enough to authenticate the node into the Tailnet. Short enough to revoke itself before the Agent can use it.