Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Suggestion] Integration of Certificate LCM with related security processes #1035

Open
knowlengr opened this issue Feb 9, 2023 · 2 comments
Labels
inactive No activity on issue/PR suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category triage-required Requires triage

Comments

@knowlengr
Copy link

Description: Add and integrate certificate management best practices, principles with other recommendations

Impact: Improve security posture for selected use cases, Enhance productivity where automation support can be added. Potentially add an additional trust layer for zero trust.

Scope: Minimally, a day of research, reading, a day of drafting with a second day to edit. A deeper, more opinionated / influential review would embed certificate recommendations into other CNCF Security TAG artifacts.

Suggested Subtopics | Selected References
SDLC, for cloud native, particularly as integrated with CI/CD but also IaC

Identify best practices for three recognized categories of SSL certificate authentication types:

  • Extended Validation (EV)
  • Organization Validation (OV)
  • Domain Validation (DV)

Protocol Support

  • ACME: Automated Certificate Management Environment
  • EST: Enrollment over Secure Transport
  • SCEP: Simple Certificate Enrollment Protocol

Asset management: Protecting digital and non-digital assets; e.g., ServiceNow ITOM

Zero trust. See AppviewX post. E.g., cert revocation offers a trust layer

Where SPIFFE fits in

Certificate Discovery

Tool stack interop: e.g., ServiceNow, Collibra

Support for metadata management

How DevOps tools leverage PKI (suggested by Appviewx)

  • Best practices for certificate management in DevOps pipelines
  • Tools that can accomplish automation and integration of PKI and DevOps

Identity & Identity Access Management: tie to certificate LCM

Service as Orchestrated, Identified Asset (See INCOSE service metamodels)

From Venafi: Figure 6: The Blueprint for a Modern Machine Identity Management Architecture

TLS in Kubernetes https://kubernetes.io/docs/tasks/tls/ and https://snyk.io/blog/setting-up-ssl-tls-for-kubernetes-ingress/

Indirectly related topics:

  • Security Operations (JSOC-administered automation and alerting)
  • assurance (cert is installed properly. is compliant, observable)
  • quality assurance (QoS, threshold monitoring, product safety)
  • integration with policy-as-code (e.g., OPA)

Related IEEE/ISO Standards

Less useful, except as applied to IoT

  • ISO 55000 Asset management — Overview, principles and terminology
  • ISO 55001 Asset management — Management systems — Requirements
  • ISO 55002:2018 Asset management — Management systems — Guidelines for the application of ISO 55001
@knowlengr knowlengr added suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category triage-required Requires triage labels Feb 9, 2023
@lumjjb
Copy link
Collaborator

lumjjb commented Feb 22, 2023

Could be relevant to #950 @achetal01 @mrsabath

@stale
Copy link

stale bot commented May 22, 2023

This issue has been automatically marked as inactive because it has not had recent activity.

@stale stale bot added the inactive No activity on issue/PR label May 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
inactive No activity on issue/PR suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category triage-required Requires triage
Projects
None yet
Development

No branches or pull requests

2 participants