so the importance of public key infrastructure and zero trust is paramount. You know things like devices, users and applications could be or should be authenticated with certificates from a public infrastructure.
So what does public key infrastructure really mean?
What it does is securely distributes and validates Public Key's in a network that is untrusted.
It's primary goal is to verify that an otherwise unprivileged user device or application is authentic. Dudes with exist in trust with very certificate authority,
or what a lot of us would call a C A.
Now the certificate authorities signs and publishes the keys that are used for validation to user's devices and the applications.
The certificate authority uses its public key
to sign the user device or applications certificate.
The sea is trusted, and it is used for other authenticating hosts on the network to validate the signature of that certificate provided by the user device for application,
you know, on the slide, we have a breakdown of the public and private keys using certificates.
Public keys are gonna be distributed, but private keys are gonna be kept secret,
you know, public. He is used to encrypt a message that only the person that has the private key can decrypt.
Now this ensures confidentiality, meaning that on the person
that the message is meant for can read it
now. Alice used her private key to send an email. Anyone that has her public, he would be able to read the message. In this scenario, we are protected the integrity of the message and whatever is in the message. We know it came from Alice, since
she is the one with the private key.
It's this level of verification. We want the router networks, and that will reduce risk.
So a quick analogy, off certificates and public key infrastructure that I've heard before would be. It's like a license plate, right. Essential authority issues the numbers and ensures
each license plate number is matched to the right vehicle.
Both drivers and police
trust this third party to keep
the right details on file, Right?
So just a quick review off what we discussed. We went over trust management,
what is trust and how strong authentication helps with manage and trust,
and we touched briefly on public key infrastructure.
So in the next section we will talk about how to trust devices,
how to trust users how to trust applications and the traffic in the zero Trust network.
Thanks for being here. Stay tuned.
So thank you for sticking with me. We've got another pop quiz. A quick learner check for the section that we just went over.
We begin with what is the least privilege
we moved to What is scope creep and then third in public key infrastructure. Who should have the private key? All things that we touched on briefly in the last section. And now we move to those answers.
So what is least privilege
least privileges? The notion that a user device or application should only be allowed the privilege is required to perform the task I was given.
Ah, quick example would be, ah, vulnerability management account. Right? If you're someone that's used some of the products out there like Ness's HQ, Wallace
or Rapid seven open boss eyes a lot to choose from.
Some of them will say that you need a domain administrative account or a local administrator account. Right? And so you know, how do we
instead of giving it full permissions to do that, how we get close to the privileges or the rights that account needs toe probe the operating system properly to give you the best assessment about the vulnerabilities, right?
So we only want to give that service account for your vulnerability management application or software the rights that needs to perform the checks it needs to do right. So least privilege needs to be applied with all users, all devices and applications. And and that's what we really mean by that and how it plays such a
and zero trust. Next we have what is scope creep? And this is the act of given permissions that are desired, more so than required and can lead to accidental misuse or intentional attacks by user device or an application. So we really have to audit, um,
our devices are users or applications and make sure that we're not giving them too much permissions. Whether it's someone gets a promotion
or we, we start to use the service account for multiple service's instead of creating a individual service count for each service or tax that we're trying to perform.
All right, so keep that in mind, and that's what zero trust is gonna allow you to do. I think about you know, how do we have the least amount of trust at least amount of privilege in our network.
Next, we've got public key infrastructure, and who should have the private key and the private key should always be in possession of the owner of the private key. Right? And you really see it in the name private. It's not something that should be publicly available, or I shouldn't be giving you my private key right? It needs to have the integrity and the
um, of the owner and nobody else. Thank you so much for sticking with me. I'll talk to you soon.