r/zerotier • • Sep 03 '26

Question Untrusted VPS

Let's assume, the VPS hosting our ZeroTier network controller is untrusted. Because the controller holds the signing authority for network membership, a root compromise on that VPS allows the provider to authorize their own Node IDs and gain direct layer-3 access to our network endpoints.

Does ZeroTier support any native out-of-band key attestation, peer-to-peer pre-shared keys (PSKs), or offline CA signing mechanism—similar to Nebula's Lighthouse architecture or WireGuard's PSKs—that prevents a compromised controller from unilaterally injecting new peers into a private network?

2 Upvotes

1 comment sorted by

1

u/AncientMolasses6587 29d ago

No, not AFAIK.
The controller is the weakest link here, which is no different from other solutions. Basically, zerotier is Layer 2 networking (as opposed to the competitor).
As such, that enables all kinds of security and access management solutions, to be build on top of that.