Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?
The PKI secrets engine is designed to support the use case of reducing and ultimately removing the use of long lived X.509 certificates. The PKI secrets engine can generate dynamic X.509 certificates on demand, with short time-to-live (TTL) and automatic revocation. This eliminates the need for manual processes of generating, signing, and rotating certificates, and reduces the risk of certificate compromise or misuse. The PKI secrets engine can also act as a certificate authority (CA) or an intermediate CA, and can integrate with external CAs or CRLs. The PKI secrets engine can issue certificates for various purposes, such as TLS, SSH, code signing, email encryption, etc. Reference: https://developer.hashicorp.com/vault/docs/secrets/pki1, https://developer.hashicorp.com/vault/tutorials/getting-started/getting-started-dynamic-secrets
Lajuana
2 months agoMarylin
2 months agoRosina
3 months agoCaren
3 months agoSerina
3 months agoEsteban
3 months agoCherry
4 months agoReuben
4 months agoFloyd
4 months agoLatonia
4 months agoLeanna
4 months agoLajuana
5 months agoLaticia
5 months agoGregoria
9 months agoDiego
10 months agoCrista
8 months agoYuette
8 months agoFletcher
9 months agoNelida
9 months agoBarney
9 months agoMiss
10 months agoDominga
9 months agoVerdell
9 months agoVincenza
9 months agoJerry
10 months agoElly
10 months agoDarci
10 months agoLyda
8 months agoTiara
8 months agoCheryl
9 months agoLashawnda
10 months agoJade
11 months agoLea
9 months agoWilda
9 months agoKatina
9 months agoJoni
9 months agoDusti
9 months agoCarlton
10 months agoAleisha
10 months agoDick
10 months agoJerry
11 months ago