3 ms·
Oh, our open source stuff has basic controls around that... using OAuth OIDC you can only get a certificate for yourself (right now it's just a direct mapping s
by mmalone 7y ago
Oh, our open source stuff has basic controls around that... using OAuth OIDC you can only get a certificate for yourself (right now it's just a direct mapping so it goes from, e.g., mike@example.com to just `mike` as the principal in the cert). For hosts our instance identity document stuff for cloud VMs can be configured to only issue certificates for the VMs hostname. Or at least it should be able to do that. I think there's a bug we're currently working on.
We also have a one-time-token mechanism that you can have some trusted infra like Puppet issue to hosts as they come up. The token includes the specific name that you want bound in the cert. It can only be exchanged for a cert with that subject.
Super secretly: we also have a whole policy language and enforcement engine that we'll eventually get around to doing something with and would address this issue pretty comprehensively.
Edit:
After reading your comment again I think I still might be misunderstanding your use case. Are you talking about having principals like "frontend" and "backend" and then having RBAC that says "mike can get a cert for frontend"?