top of page

Red Team Training Starts 24th October, 2026

Technical Talk

One Key to Sign Them All : Forging Service Identity at the Mesh Boundary

DATE

27 October 2026

LOCATION

Hilton EGL, Bangalore

TIME

14:30 - 15:15

Abstract

Every service mesh gives each pod a cryptographic mTLS identity, but that identity is scoped to the connection. Inside the mesh, sidecar to sidecar, it's strictly enforced. The moment a request crosses a TLS-terminating boundary like an ingress or a hop to another cluster, the peer certificate doesn't travel with it, so the original identity can't cross the boundary and the platform falls back to a signed JWT minted by a gateway from a single private key. Where identity gets re-derived, and who can hold that key, decide whether the whole mesh can be impersonated.

​

We red-teamed a multi-cluster Kubernetes and Istio platform to test that model. Mapping which pods and IAM roles could read the signing key, we found it readable from more than one place, enough to mint a JWT claiming to be any service. Yet forging identity against an internal service failed three ways: the egress gateway re-signs the JWT from the caller's real mTLS certificate, Istio RequestAuthentication strips attacker-supplied claims, and an AuthorizationPolicy allowlist blocks the rest. We reproduce all three and show how we confirmed our forged identity was being overwritten.​

One Key to Sign Them All.png

Then we found the service that skipped those controls, a sensitive API reached through an ingress with no re-signer and no binding between caller and target. There, identity is trusted exactly as presented. One signed request returns any user's data and bypasses pre-authentication.

​

You'll leave with:

Two invariants that decide every outcome :
1.  provenance (is identity re-derived from the certificate at each boundary?) and 
2. custody (who can hold the signing key?)
How to threat-model identity propagation, and why the deciding variable isn't traffic direction or cluster crossings but whether a boundary re-signs
Why mesh mTLS is  not sufficient, and what to audit instead

MEET THE INSTRUCTOR

Sweta Mantraratnam

Sweta Mantraratnam.jpeg

Security Architect

Sweta mantraratnam, security architect currently working with JP Morgan Chase London with over 12 years of experience specializing in security architecture, threat modeling, and cloud security.

About AltSecCON

AltSecCON is an in-person Red Team training initiative focused on instructor-led delivery, enterprise-aligned labs, and practical offensive security execution.
 

​© AltSecCON. An Altered Security initiative.
contact@alteredsecurity.com

Information

Training Programs

Follow Us

  • X
  • LinkedIn
  • Discord
  • Facebook
  • Instagram

Conference

Event

© 2026 AltSecCON. All rights reserved.

bottom of page