Top Banner
1 BEYOND SECRET STORAGE Brett Mack @phpops Using Vault & The PKI Backend To Harden Your Infrastructure
18

Vault: Beyond secret storage - Using Vault to harden your infrastructure

Jan 11, 2017

Download

Technology

opencredo
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Vault: Beyond secret storage - Using Vault to harden your infrastructure

1

BEYOND SECRET STORAGE

Brett Mack@phpops

Using Vault & The PKI Backend To Harden Your Infrastructure

Page 2: Vault: Beyond secret storage - Using Vault to harden your infrastructure

2

ABOUT ME

BRETT MACK

DevOps Consultant OpenCredo

Page 3: Vault: Beyond secret storage - Using Vault to harden your infrastructure

3

Agenda

• What is PKI • How can we achieve this with Vault • Brief Demo • Issues we encountered • Conclusion / Where we go from here

Page 4: Vault: Beyond secret storage - Using Vault to harden your infrastructure

4

What is PKI

Source: photobucket.com

Tell me whyTell me why, PKI?

Page 5: Vault: Beyond secret storage - Using Vault to harden your infrastructure

5

Page 6: Vault: Beyond secret storage - Using Vault to harden your infrastructure

6

https://aphyr.com/tags/jepsen

Page 7: Vault: Beyond secret storage - Using Vault to harden your infrastructure

7

http://twitter.com/swiftonsecurity

Page 8: Vault: Beyond secret storage - Using Vault to harden your infrastructure

8

http://twitter.com/swiftonsecurity

Page 9: Vault: Beyond secret storage - Using Vault to harden your infrastructure

9

What is PKI

A public key infrastructure (PKI) supports the distribution and identification of public encryption keys, enabling users and computers to both securely exchange data

over networks such as the Internet and verify the identity of the other party

Page 10: Vault: Beyond secret storage - Using Vault to harden your infrastructure

10

What is PKI

X.509

X.509v3 - PKIX

Page 11: Vault: Beyond secret storage - Using Vault to harden your infrastructure

11

What is PKI

Certificate

Page 12: Vault: Beyond secret storage - Using Vault to harden your infrastructure

12

What is PKI

Intermediate CA

Certificate

Page 13: Vault: Beyond secret storage - Using Vault to harden your infrastructure

13

What is PKI

ROOT CA

Intermediate CA

Certificate

Page 14: Vault: Beyond secret storage - Using Vault to harden your infrastructure

14

DEMO

Page 15: Vault: Beyond secret storage - Using Vault to harden your infrastructure

15

Issues

Page 16: Vault: Beyond secret storage - Using Vault to harden your infrastructure

16

Where to go from here

Content-Security-Policy

Public-Key-Pins

Strict-Transport-Security

Page 17: Vault: Beyond secret storage - Using Vault to harden your infrastructure

17

Page 18: Vault: Beyond secret storage - Using Vault to harden your infrastructure

18

We’re Hiring

https://opencredo.com

https://opencredo.com/blog

https://github.com/opencredo/vault-pki-demo