
5/29/2019 · Neel Goyal, Kyle Nekritz, Subodh Iyengar
What this post added
This post details Meta's migration of its internal data center service encryption from Kerberos to TLS. It highlights the challenges of managing Kerberos at scale, leading to the adoption of TLS with X.509 certificates for improved operability and performance. Key contributions include the design principles for managing the security-operability trade-off, the use of session tickets for efficient symmetric key cryptography, and the development of an internal certificate authority (ICA) for robust identity provisioning during container setup, ensuring end-to-end defense in depth for microservices.