securing cloud servers and services with pki …...tmw04 – securing cloud servers and services...

30
TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level: Intermediate

Upload: others

Post on 06-Jun-2020

22 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

TMW04 – Securing Cloud Servers and

Services with PKI Certificates

Mark B. CooperPresident & Founder

PKI Solutions Inc.

Level: Intermediate

Page 2: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

About PKI Solutions Inc.

• 10 years as “The PKI Guy” @ Microsoft

• Charter – Microsoft Certified Master DS

• Numerous books and whitepapers

• Services include:

• ADCS Architecture, Deployment and Consulting

• Assessment and Remediation Services

• In-Depth PKI Training

SFO January 2015, NYC February 2015

• Retainer and Support Services

Page 3: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Agenda

• It’s all about security

• Data and identity protection

• Hybrid PKI solutions

• Bring your own key

• Cloud-based solutions

• Security considerations

Page 4: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Security

Page 5: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Human nature and security

• Humans are inherently security conscience

– Information is not

• Technology can define procedures

• Human nature trumps every time

• Constant struggle to protect and assure

• Need to define methods to elevate security

Page 6: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

The cloud

• Push to cloud changes paradigms

• Organizations moving data to the

cloud

• Security needs to adapt and adopt

• Lock and keys in the same place

Page 7: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Data and identity

protection

Page 8: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Public Key Infrastructure

• Increases assurance of data and identities

• Reduces ambiguity in the enterprise

• Information protection

– Signing/Assurance

– Encryption/Protection

Page 9: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

The certificate

• Signing and/or encryption

• Unique identification of someone or

something

• Limited in scope and use by an authority

• Principles of private key instance

ownership

• Guaranteed uniqueness

– Non-Repudiation

Page 10: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Hybrid PKI solutions

Page 11: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Traditional PKIs

Three Tier Two Tier

Root CA

Policy CA

Issuing CA

Root CA

Issuing CA

Page 12: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Simple hybrid

Root CA

Issuing CA

• Easiest solution

• Subordinate role in

the cloud

– Root secured on premise

• Greatest risk

– Unrestricted issuance

– Signing keys

– Remote administration

Page 13: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Dual hybridRoot CA

Issuing CA

• Onsite and cloud

• Dynamic and elastic

• Preserves root

– Root secured on premise

• Same risks as simple

– Unrestricted issuance

– Signing keys

– Remote administration

Issuing CA

Page 14: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Not in my cloud you don’tRoot CA

Issuing CA

• Onsite and cloud

• Dynamic and elastic

• Preserves root

– Root secured on premise

• Same risks as simple

– Unrestricted issuance

– Signing keys

– Remote administration

Page 15: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

The restricted approach

• True hybrid

• Policy restricts cloud

issuance

• Compromises are

limited

• Technically possible

with 2-tier*

• Some risks remain

– Signing keys

– Remote administration

Root CA

Policy CA

Issuing CA

Page 16: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Bring your own key

Page 17: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Trust but restrict

• Local key management

• Create and manage key locally

– Generally in a Hardware Security Module

• Key is restricted and placed in cloud

• Cradle to grace security is difficult

– Generate and then secure in transit to known service

• Few services ready today

– Microsoft Azure Rights Management Server

Page 18: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Cloud based solutions

Page 19: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Cloud – all in

• It’s all about the keys

• Adopt industry signing key practices to

the cloud

– Not easy in VM environment either

• Physical controls removed between keys

and attacker

– Your admin is their entry door

• Opposed to elastic concepts in cloud

computing

Page 20: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Cloud PKI – Soft keys

• Software key protection

• Limited isolation of root

• Risks shifted to provider

• Dynamic over secure

• It’s cloud and not much

else

Root CA

Issuing CA

Page 21: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Cloud PKI – Hard keys

• Hardware key protection

– Virtualized HSM access

• Limited providers

• Co-Mingling of keys

• Key propagation

• Provider key protections

• Mitigates some key risks

• Risks remain

Issuing CA

Root CA

Page 22: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Bring your own HSM

• Theoretical concept

– Not for everyone or all circumstances

• Breaks many conventional security practices

• Shifts risks and manages exposure

• Hybrid concept of BYOK, Cloud and legacy

• Ask me next year how I feel

– Body of practices and security practices to be defined

Page 23: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Issuing CA

Net HSM

Corporate

Firewall

Connection

Secure

Connection

Page 24: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Why Bother?

• Local key management

• Security defined around core risk

• Shifts service, but not risk

• Data and key are not stored near each other

• Compromise of one doesn’t affect the other

• Still enables full cloud migration in the future

Page 25: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Ideal cloud architecture

• No one architecture works for everyone

• Cloud forces reconsideration of tier models

– Modern architecture moved to two-tier

– Cloud is begging for three-tier

• Combination of on premise and hybrid

• At least a starting point in the design

discussion

Page 26: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Root CA

Policy CA

HSM

HSM

Explicit

Issuance Policies

Issuing CA

Cloud HSMCloud HSM

Service

Issuing CA

HSM

Page 27: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Security considerations

Page 28: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Follow the keys

• PKI keys are the core of trust and assurance

• Determine storage and access to keys

– Logical and physical

• Ensure policies and procedures define

access

• Eliminate redundant and superfluous access

– Provider limitations and controls

• Determine acceptable risk levels and mitigate

• Security trumps rush to the cloud

Page 29: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Agile PKI

• PKI can be defined for future migrations

• Elastic design and agility are possible

• Reduces future migration effort

• Build today with an eye on tomorrow

Page 30: Securing Cloud Servers and Services with PKI …...TMW04 – Securing Cloud Servers and Services with PKI Certificates Mark B. Cooper President & Founder PKI Solutions Inc. Level:

Questions?

pkisolutions.com

[email protected]

@pkisolutions