Hello,
I'd like to hear your opinion and share experience.
This post is not related to FreeBSD.
Background:
We have a enterprise OnPrem environment with the following setup:
Security team requires regular certificate rotation.
I'm looking at:
- HashiCorp Vault
Has anyone implemented something like this?
What's the easiest way to automatically issue short-lived SSH certificates to many users?
What works best in practice?
I'd like to hear your opinion and share experience.
This post is not related to FreeBSD.
Background:
We have a enterprise OnPrem environment with the following setup:
- Users: 1,000+
- Infrastructure: 400+ Windows/Unix VMs.
- Authentication: Microsoft Active Directory for user accounts, with passwords expiring every 45 days.
Security team requires regular certificate rotation.
I'm looking at:
- HashiCorp Vault
Has anyone implemented something like this?
What's the easiest way to automatically issue short-lived SSH certificates to many users?
What works best in practice?