Controlled Identity Enrollment
OpenZiti identities are created and enrolled through an authorized enrollment process.
Ensure that only approved devices become Zero Trust identities.
Modern organizations increasingly use Zero Trust Network Access (ZTNA) to provide application connectivity based on verified identities rather than traditional network location.
A Zero Trust architecture must control not only which users can access applications, but also which devices and identities are permitted to join the protected network.
OpenZiti is an open-source Zero Trust networking platform that uses identities and enrollment mechanisms to establish secure access to services.
If an attacker obtains or misuses a legitimate enrollment mechanism, they may attempt to register a rogue device as a trusted identity. If that unauthorized identity receives excessive service permissions, it may gain access to protected applications.
In this use case, OpenZiti is deployed as the controlled Zero Trust networking platform on Ubuntu Linux inside an isolated VirtualBox laboratory.
A protected internal web application is deployed as the target service. Authorized and unauthorized laboratory identities are used to establish the expected access model.
A controlled Rogue Device Enrollment Attack is simulated using a laboratory enrollment credential. The objective is to determine whether an unauthorized device can enroll into the OpenZiti network and obtain access to a protected service.
OpenZiti identity and service policies are used to control access. OpenZiti Controller logs provide identity and enrollment telemetry, while auditd monitors relevant host activity.
Wazuh is used for centralized security monitoring, and OpenSearch is used for security investigation and event correlation.
After identifying the enrollment weakness, enrollment credentials and identity policies are strengthened. The unauthorized identity is removed or revoked, and the same controlled enrollment scenario is repeated to verify that rogue devices cannot obtain protected-resource access while legitimate identities continue to function.
The complete Zero Trust workflow is: Protected Application → OpenZiti Zero Trust Network → Identity Enrollment → Authorized Device → Service Policy → Controlled Enrollment Credential Exposure → Rogue Device Enrollment → Identity Validation → Access Decision → Security Detection → Identity Revocation → Policy Remediation → Retesting → Zero Trust Validation
OpenZiti is the real open-source Zero Trust networking platform used in this project.
Zero Trust access depends on correctly managed identities. If an enrollment credential is improperly protected or an identity is granted excessive permissions, an unauthorized device may attempt to enroll as a trusted OpenZiti identity.
The security problem is therefore:
The controlled attack scenario evaluates whether an unauthorized laboratory device can use a compromised or improperly protected enrollment mechanism to obtain an OpenZiti identity.
The primary Zero Trust security concept is Identity-Centric Access Control with Continuous Authorization.
A device should not become trusted merely because it successfully connects to the Zero Trust network. Instead, the enrollment and access process should follow: Device → Enrollment Request → Identity Verification → Identity Authorization → Service Policy Evaluation → Access Decision → Protected Resource. The objective is to ensure that obtaining an enrollment mechanism does not automatically provide unrestricted access to protected applications.
The secure processing flow is:
OpenZiti identities are created and enrolled through an authorized enrollment process.
Ensure that only approved devices become Zero Trust identities.
Enrollment credentials are securely managed and restricted.
Reduce the risk of unauthorized identity enrollment.
OpenZiti identities are reviewed, approved, revoked, and removed according to their lifecycle state.
Prevent stale or unauthorized identities from remaining active.
Identities receive access only to services required for their legitimate purpose.
Reduce the impact of a compromised identity.
Access to protected applications is evaluated using OpenZiti service policies.
Prevent network membership from automatically granting application access.
Unauthorized or compromised identities are revoked.
Immediately remove unauthorized device access.
Identity enrollment activity is monitored.
Detect unexpected or suspicious identity creation.
Linux audit telemetry is collected from the OpenZiti environment.
Provide visibility into identity-management and system activity.
Wazuh collects relevant security events.
Provide centralized detection and monitoring.
OpenSearch correlates enrollment, identity, and host events.
Establish the sequence and impact of suspicious enrollment activity.
The rogue enrollment scenario is repeated after remediation.
Verify that unauthorized identities cannot obtain protected-resource access.
OpenZiti is the primary Zero Trust networking platform.
The OpenZiti CLI is used to manage laboratory identities and enrollment operations.
auditd monitors relevant Linux security activity.
Wazuh provides centralized security monitoring.
OpenSearch provides centralized security investigation.
A controlled internal web application is deployed as the protected resource.
Ubuntu hosts the OpenZiti environment and protected application.
Kali Linux provides the controlled rogue-device environment.
VirtualBox provides the isolated Zero Trust laboratory.