Application Security and Permissions
Using short-lived certificates to protect TLS secrets

Using short-lived certificates to protect TLS secrets

8/7/2023 · Rachana Nandan, Kyle Nekritz, Jacob Courtneay, Zale Young, Ameya Shendarkar

What this post added

Introduced short-lived certificates (SLCs) for TLS private keys on edge networks, reducing certificate validity from months/years to days (specifically 10 days exposure, daily rotation). This involved building a robust automation pipeline (ConfigBuilder) for certificate issuance and distribution, enhancing the OffloadService to handle frequent secret fetches, and implementing a staged rollout process with canaries and wider deployments to ensure reliability. Explored and rejected protocol layer revocation and remote offload due to latency and reliability concerns. Also experimented with delegated credentials but noted browser adoption limitations.

Read the original post ↗