12
digital.Media.Solutions © AMAN Media GmbH – Jens Rosenthal digital.Media.Solutions Munich, May 2018 PKI AUTOMATION IN THE CLOUD

PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

  • Upload
    others

  • View
    12

  • Download
    0

Embed Size (px)

Citation preview

Page 1: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

Munich, May 2018

PKI AUTOMATION IN THE CLOUD

Page 2: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

PKI - THE INFRASTRUCTURE

Online - AWS Cloud

Server EU

Server EU

OCSP Integ.

Server EU

Server EU

OCSP US

Server EU

Server EU

OCSP EU

Offline - inaccesible Offline

Root CA

TLS CA

Backend CA

Client CA

TLS EU CA

TLS US CA

TLS Integ. CA

Client EU CA

Client US CA

Client Integ. CA

Server EU

Server EU

Server EU

Server US

Server US

Server US

Server AP

Server AP

Server Integ.

Page 3: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

CHALLENGES & RISKS

Challenges:

● Multiple environments

○ Multiple CAs

○ DN naming structure

○ Overview

● Multiple suppliers

● Scaling of instances

● CRL maintenance

Risks:

● Human factor

○ CSRs with wrong DNs

○ CSRs with identical keys

○ CRTs from wrong CA

○ CRTs from wrong CSR

● Response time

○ manual effort during scaling

Page 4: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

SOLUTION: AUTOMATION

Semi-automated workflow:Provisioning of a new container

(CA, OCSP, Server)

Automated PKI setup(generate Key and CSR)

Automated CSR submission(PKI Proxy)

Manual CSR submission(PKI Proxy)

Offline signing(with validation)

Manual CRT submission

Automated CRT download(PKI Proxy)

Manual CRT download(PKI Proxy)

Page 5: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

STEP-BY-STEP: UPLOAD CSR

Page 6: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

STEP-BY-STEP: UPLOADED CSR

Page 7: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

STEP-BY-STEP: ADD DETAIL INFORMATION

Page 8: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

STEP-BY-STEP: ADD VALIDATION INFORMATION

Page 9: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

STEP-BY-STEP: VALIDATE AND SIGN CSR

Page 10: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

STEP-BY-STEP: DOWNLOAD SIGNED CRT

Page 11: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

SOLUTION: AUTOMATION

Benefits:

● Validation○ of DNs in CSRs○ of signed CRTs

● Assistance○ automated assignment of signing CAs○ automated assignment of certificate purpose○ documentation○ overview

● Self-Service○ semi automated process○ authentication / authorization○ faster

Page 12: PKI AUTOMATION IN THE CLOUD...Online - AWS Cloud Server EU Server EU OCSP Integ. Server EU Server EU OCSP US Server EU Server EU OCSP EU Offline - inaccesible Offline Root CA TLS CA

digital.Media.Solutions

© AMAN Media GmbH – Jens Rosenthal

digital.Media.Solutions

QUESTIONS?

Time for questions

JENS ROSENTHALSoftware Architect

AMAN digital media solutionswww.aman.de / [email protected]