Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-2029

Review the need for External CA for Platform Certificates

XMLWordPrintable

    • Product / Portfolio Work
    • OCPSTRAT-2568Enhanced Platform Certificate Lifecycle Management and Compliance
    • Hide

      Status : Yellow
      As discussed last week this Feature will be moving out of 4.21. I have asked Luis to provide the lastest update with where we stand with the requested functionality.

      Show
      Status : Yellow As discussed last week this Feature will be moving out of 4.21. I have asked Luis to provide the lastest update with where we stand with the requested functionality.
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Feature

      The requirement to integrate with external enterprise Certificate Authority (CA) systems is driven by security and compliance demands from customers, including those in the Government and Telco sectors.

      The focus is on implementing an Intermediate Signing CA Strategy to satisfy compliance needs while maintaining OpenShift's operational integrity.

      Mechanism

      OpenShift will be configured to accept an intermediate signing certificate (Intermediate CA) provided by the external authority as an input (e.g. during installation).

      Result 

      This allows OpenShift to use its existing internal, automated PKI mechanisms for tasks like bootstrapping, rotation, and self-healing, while all platform certificates are ultimately chained to the customer's trusted enterprise root CA.

      Scope Rationale

      After extensive review, the project scope has undergone a strategic shift based on the consensus that a full external CA integration for internal platform certificates would be overly complex, introduce new points of failure, compromise OpenShift's automated life cycle management, and conflict with core reliability design principles.

              racedoro@redhat.com Ramon Acedo
              racedoro@redhat.com Ramon Acedo
              None
              None
              Seth Jennings Seth Jennings
              Kaleemullah Siddiqui Kaleemullah Siddiqui
              Andrea Hoffer Andrea Hoffer
              Kyle Walker Kyle Walker
              Votes:
              1 Vote for this issue
              Watchers:
              17 Start watching this issue

                Created:
                Updated: