Red Team Training Starts 24th October, 2026
Technical Talk
One Key to Sign Them All : Forging Service Identity at the Mesh Boundary
DATE
27 October 2026
LOCATION
Hilton EGL, Bangalore
TIME
14:30 - 15:15
Abstract
Every service mesh gives each pod a cryptographic mTLS identity, but that identity is scoped to the connection. Inside the mesh, sidecar to sidecar, it's strictly enforced. The moment a request crosses a TLS-terminating boundary like an ingress or a hop to another cluster, the peer certificate doesn't travel with it, so the original identity can't cross the boundary and the platform falls back to a signed JWT minted by a gateway from a single private key. Where identity gets re-derived, and who can hold that key, decide whether the whole mesh can be impersonated.
We red-teamed a multi-cluster Kubernetes and Istio platform to test that model. Mapping which pods and IAM roles could read the signing key, we found it readable from more than one place, enough to mint a JWT claiming to be any service. Yet forging identity against an internal service failed three ways: the egress gateway re-signs the JWT from the caller's real mTLS certificate, Istio RequestAuthentication strips attacker-supplied claims, and an AuthorizationPolicy allowlist blocks the rest. We reproduce all three and show how we confirmed our forged identity was being overwritten.
Then we found the service that skipped those controls, a sensitive API reached through an ingress with no re-signer and no binding between caller and target. There, identity is trusted exactly as presented. One signed request returns any user's data and bypasses pre-authentication.
You'll leave with:
Two invariants that decide every outcome :
1. provenance (is identity re-derived from the certificate at each boundary?) and
2. custody (who can hold the signing key?)
How to threat-model identity propagation, and why the deciding variable isn't traffic direction or cluster crossings but whether a boundary re-signs
Why mesh mTLS is not sufficient, and what to audit instead
MEET THE INSTRUCTOR
Sweta Mantraratnam

Security Architect
Sweta mantraratnam, security architect currently working with JP Morgan Chase London with over 12 years of experience specializing in security architecture, threat modeling, and cloud security.
About AltSecCON
AltSecCON is an in-person Red Team training initiative focused on instructor-led delivery, enterprise-aligned labs, and practical offensive security execution.
© AltSecCON. An Altered Security initiative.
contact@alteredsecurity.com
Information
Training Programs
Follow Us
Conference
Event
© 2026 AltSecCON. All rights reserved.


