Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-2029

Review the need for External CA for Platform Certificates

XMLWordPrintable

    • Product / Portfolio Work
    • OCPSTRAT-2568Enhanced Platform Certificate Lifecycle Management and Compliance
    • Hide

      Status : Yellow
      As discussed last week this Feature will be moving out of 4.21. I have asked Luis to provide the lastest update with where we stand with the requested functionality.

      Show
      Status : Yellow As discussed last week this Feature will be moving out of 4.21. I have asked Luis to provide the lastest update with where we stand with the requested functionality.
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Feature

      There are multiple security regulations that involve certificate management. OpenShift uses internally certificates between services that will never be exposed to the outside.

      There are other services the platform provides that are external facing, for which the cert-manager operator can already manage certificates with an external CA.

      RHACM along with Hosted Control Planes can also manage the Hosted Clusters certificates via cert-manager in the RHACM hub / management cluster (tgeer@redhat.com to review).

      Goals

      • Evaluate requirements including:
        • Customers in Telco. Including request to support for the CMPv2 protocol (RFC 4210) for obtaining and managing the lifecycle of the platform certificates.
      • Integration with NSA Type 1 encryption external CAs:
      • Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI): Does OpenShift's management of the platform certificate s comply with ANSSI's guidelines about the use of private CAs with regards to PKI security?
      • Does the EU Cybersecurity Act / EU Common Criteria include additional criteria OpenShift is or isn't compliant?

              racedoro@redhat.com Ramon Acedo
              racedoro@redhat.com Ramon Acedo
              None
              None
              Seth Jennings Seth Jennings
              Kaleemullah Siddiqui Kaleemullah Siddiqui
              Andrea Hoffer Andrea Hoffer
              Kyle Walker Kyle Walker
              Votes:
              1 Vote for this issue
              Watchers:
              15 Start watching this issue

                Created:
                Updated: