Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discussion: L3AFD Secure web api #20

Merged
merged 10 commits into from Apr 7, 2022

Conversation

sanfern
Copy link
Contributor

@sanfern sanfern commented Mar 1, 2022

Signed-off-by: Santhosh Fernandes santhosh.fernandes@gmail.com

Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
@dalalkaran
Copy link
Contributor

LGTM, thanks to everyone for their input/feedback!

Copy link
Contributor

@dalalkaran dalalkaran left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM :)

Copy link
Contributor

@jniesz jniesz left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
Copy link
Collaborator

@dthaler dthaler left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few wording nits and then good

discussions/secure_web_api.md Outdated Show resolved Hide resolved

L3AF could be running in two scenarios, users can use L3AF in secure enterprise private networks and in public network.
In case of private network, L3AFD and clients will be communicating with each other over a network that is normally
protected by vpn or PCI (Payment Card Information), and hence it may not be essential to enable mTLS in this case.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
protected by vpn or PCI (Payment Card Information), and hence it may not be essential to enable mTLS in this case.
protected by vpn or PCI (Payment Card Information), and hence some may not consider it essential to enable mTLS in this case, although the current industry trend and best practice is to consider it essential even on private networks, which trend uses the [Zero trust security model](https://en.wikipedia.org/wiki/Zero_trust_security_model).

discussions/secure_web_api.md Outdated Show resolved Hide resolved
discussions/secure_web_api.md Outdated Show resolved Hide resolved
Signed-off-by: Santhosh Fernandes <santhosh.fernandes@gmail.com>
Copy link
Collaborator

@dthaler dthaler left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for all the updates! Looks good now.

@sanfern sanfern merged commit 568413b into l3af-project:main Apr 7, 2022
@sanfern sanfern deleted the sanfern-secure-web-api branch April 7, 2022 01:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants