zerotrust.supply

Match

A file name is not an identity.

The allow key is Team ID, Signing ID, cdhash, domain, and port. A full path may be added, and then it must match together with the cdhash.

01

Signature

Team ID plus Signing ID. An ad-hoc signature has no Team ID, so it misses a rule that names one.

02

cdhash

Read from this flow's audit token at decision time. Replacing the file at the same path changes the hash.

03

Entire path

Segment by segment. Not the file name, not a prefix. The same name in another directory does not match.

The decision and the forward are the same flow.

A domain with no port allows every port on that name. Switching to another address after DNS is not a match. The access point dials the upstream in the snapshot, not an IP the client resolved later.

Swift does not compare these fields. The comparison is Go. The Go runtime is not embedded in the extension process.

Back to the front page