Your organization has an initiative to reduce and ultimately remove the use of long lived X.509 certificates. Which secrets engine will best support this use case?
The PKI secrets engine is designed to support the use case of reducing and ultimately removing the use of long lived X.509 certificates. The PKI secrets engine can generate dynamic X.509 certificates on demand, with short time-to-live (TTL) and automatic revocation. This eliminates the need for manual processes of generating, signing, and rotating certificates, and reduces the risk of certificate compromise or misuse. The PKI secrets engine can also act as a certificate authority (CA) or an intermediate CA, and can integrate with external CAs or CRLs. The PKI secrets engine can issue certificates for various purposes, such as TLS, SSH, code signing, email encryption, etc. Reference: https://developer.hashicorp.com/vault/docs/secrets/pki1, https://developer.hashicorp.com/vault/tutorials/getting-started/getting-started-dynamic-secrets
Lajuana
4 months agoMarylin
4 months agoRosina
4 months agoCaren
5 months agoSerina
5 months agoEsteban
5 months agoCherry
5 months agoReuben
6 months agoFloyd
6 months agoLatonia
6 months agoLeanna
6 months agoLajuana
6 months agoLaticia
6 months agoGregoria
11 months agoDiego
11 months agoCrista
10 months agoYuette
10 months agoFletcher
10 months agoNelida
10 months agoBarney
11 months agoMiss
12 months agoDominga
10 months agoVerdell
11 months agoVincenza
11 months agoJerry
12 months agoElly
12 months agoDarci
12 months agoLyda
10 months agoTiara
10 months agoCheryl
11 months agoLashawnda
11 months agoJade
1 year agoLea
10 months agoWilda
11 months agoKatina
11 months agoJoni
11 months agoDusti
11 months agoCarlton
11 months agoAleisha
11 months agoDick
12 months agoJerry
1 year ago