A company is using the PKI secrets engine to issue certificates for internal services. They want to ensure that certificates are automatically revoked if a service is decommissioned. What should they implement?
Trap 1: Implement certificate pinning in all services.
Pinning is a security measure, not a revocation mechanism.
Trap 2: Set a very short TTL on certificates so they expire quickly.
Short TTL reduces risk but does not revoke; service still valid until expiration.
Trap 3: Configure a Certificate Revocation List (CRL) that clients check.
CRL is a mechanism for clients to check revocation, not automatic revocation.
- A
Implement certificate pinning in all services.
Why it fails: Pinning is a security measure, not a revocation mechanism.
- B
Use Vault's built-in lifecycle management and revocation capabilities.
Vault's PKI secrets engine supports lease-based certificate issuance, so certificates carry a TTL and are revoked automatically when the lease expires or is revoked. Decommissioned services stop renewing, and their certificates lapse without manual intervention.
- C
Set a very short TTL on certificates so they expire quickly.
Why it fails: Short TTL reduces risk but does not revoke; service still valid until expiration.
- D
Configure a Certificate Revocation List (CRL) that clients check.
Why it fails: CRL is a mechanism for clients to check revocation, not automatic revocation.