A platform team manages a fleet of on-premises Linux servers that are not joined to any cloud provider or Active Directory domain. They want each server to authenticate to Vault automatically at boot without embedding a long-lived token in a configuration file. The team already maintains an internal PKI that issues X.509 certificates to every server. Which authentication method should they enable to meet these requirements with the least new infrastructure?
The cert auth method validates the client certificate presented during the TLS handshake against a CA certificate configured on the mount. Because the internal PKI already issues certificates to every server, the team reuses existing infrastructure rather than deploying new credential stores or cloud integrations. This satisfies the requirement of automatic, token-free authentication at boot.
Why this answer
Certificate authentication leverages the PKI certificates the servers already possess, so no new credential distribution channel is needed. During the TLS handshake the server presents its certificate, and Vault validates it against the trusted CA configured on the cert mount. This yields automatic, secret-free login for on-premises hosts that have no cloud identity.
Exam trap
The trap here is assuming that any machine-to-machine method works everywhere, when cloud identity methods like aws auth only function for workloads that actually have a cloud-issued identity.