3 ms·
Can't speak to my current employer as it's above my pay-grade to know, but at Job-1 we did the following: - All "hot" keys were stored in an offline credential
by openfinch 6y ago
Can't speak to my current employer as it's above my pay-grade to know, but at Job-1 we did the following:
- All "hot" keys were stored in an offline credential manager in specific vaults depending on who needed access to them. Only staff with actual clearance could request temporary access to a vault (fully background checked, 1 year employment, etc).
- Copies of each vaulth and our master CA cert were written to 4 encrypted USB sticks. Two stored on-site in the fire-safe and two off-site at our safety deposit box that only c-level staff could access. (We had the same process with our tokens and master logins for AWS).
- Any work using those keys was on a pair-up basis, so at least two people, one doing the work and the other observing.
- We had a detailed policy around this that covered each step in the process and who needs to approve them; everyone who could feasibly need to access the keys was briefed annually as part of our security awareness training.
We handled a LOT of sensitive financial data, so this was the most appropriate way that we could find that maintained both sensible availability and key control.
So in order to get to the keys you needed:
- Access to the fire safe (Senior Ops, Senior Security and C-Level only).
- The LUKS passphrase for the USB sticks (Senior Security and some C-Level only).
- The passphrase for the specific vault (Senior Security and some C-Level only).
I don't know how the passphrases were managed by our sec team, but I know that the C-Level staff had physical envelopes in their home safes.
- brutus1213 6y agoAn expanded version of this would make a valuable book (or blog post at least).
- deleted 6y ago[deleted]
- closeparen 6y agoHow did you handle new secrets / rotations? Seems like a lot to keep in sync. Seems like we hear more frequently about the actual secrets being stored encrypted (potentially with hardware protection) in a central place, and only the keys to unlock them being distributed like this.
- tomschlick 6y agoNot OP, but generally you wouldnt distribute the actual passphrases to the people who keep hard copy backups. You'd distribute the key to unlock the key. That way you could rotate the actual key and you just re-encrypt it with the secrets you already distributed.