Is there any solution to this older GitHub issue yet?
In summary, is there a way to set a "dial only" setting on the tunneler side to ensure that an OpenZiti administrator cannot successfully use that identity as a bind target? This is a security issue from the perspective of someone joining a network where they may not fully trust the administrators, or even where the tunneler is on a secured machine that needs to reach out to things but should never have inbound access in any situation.
Hi @Krishopper, I fully understand where you're coming from. At this time there has been no effort put into a "dial only" sort of identity/tunneler setting. It does come back around from time to time, but it hasn't reached a tipping point of prioritization just yet.
Hi @Krishopper - we've done some foundational work and have early proof-of-concept-level functionality targeted at this use case that might be relevant to you. If you're open to a 1-1 Zoom call, I can discuss with you in more detail, and possibly give you early access. Send me a DM if you're interested.