Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-1043

[SC-12,SC-12(2),SC-12(3)]: Internal certificates

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Critical Critical
    • 2021Q4 Plan
    • None
    • None
    • None
    • 1
    • False
    • False
    • OCPPLAN-6104 - FedRAMP moderate controls
    • Undefined
    • CMP Sprint 37

      This card is a continuation of CMP-942, covering external certificates. Please see CMP-942 for the full discussion. SC-12 as a whole is an organizational control (see e.g. this issue. However, we should still provide some guidance.

      External certs are handled in card CMP-1042.

      Internal certs are issued by a self-signed CA. At the very minimum, we should polish our response why is it OK.

      We also used to have a card that tracked creating a map of certs and CAs, perhaps we should resurrect it.

      Acceptance Criteria

      • Include verbiage in controls structe in CaC

              jhrozek@redhat.com Jakub Hrozek (Inactive)
              jhrozek@redhat.com Jakub Hrozek (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: