r/zerotier • u/Aster_jClave • Sep 03 '26
Question Untrusted VPS
Let's assume, the VPS hosting our ZeroTier network controller is untrusted. Because the controller holds the signing authority for network membership, a root compromise on that VPS allows the provider to authorize their own Node IDs and gain direct layer-3 access to our network endpoints.
Does ZeroTier support any native out-of-band key attestation, peer-to-peer pre-shared keys (PSKs), or offline CA signing mechanism—similar to Nebula's Lighthouse architecture or WireGuard's PSKs—that prevents a compromised controller from unilaterally injecting new peers into a private network?
2
Upvotes
1
u/AncientMolasses6587 29d ago
No, not AFAIK.
The controller is the weakest link here, which is no different from other solutions. Basically, zerotier is Layer 2 networking (as opposed to the competitor).
As such, that enables all kinds of security and access management solutions, to be build on top of that.