Key and certificate management considerations

I deploy hundreds / thousands of small servers that communicate with my hosted motherhood through HTTPS and ssh.

What are the best practices for managing SSL client certificates (for https) and ssh keys when revocation may be required? I think about issues like distributing keys / certificates for change, revocation management when a separate ssh key is required, rather than a shared one ...

+3
source share
2 answers

Create a key on the client, save the key pair in the SQLite database (preferably encrypted), transfer the public key to the server using web methods and save it there.

, .

( )

, .

+1

Enterprise-, , Director Encryption Director: http://www.venafi.com/Products/Venafi-Encryption-Director/ , , .

(http://www.kousec.com/download.html), , .

+1

Source: https://habr.com/ru/post/1773816/


All Articles