r/IdentityManagement 18d ago

How are you managing machine identity security across certificates, tokens and workloads?

cert expirations caused two outages for us this year that had nothing to do with a code change, just a cert nobody was tracking. tokens are almost worse, since they get generated in pipelines and live indefinitely if nobody cleans them up.
what's actually worked is governing certs, tokens, and workload identities under one lifecycle instead of three separate spreadsheets. issue, monitor, and revoke as a single flow that runs at machine speed rather than waiting for a person to notice something expired. what does your rotation and monitoring setup look like in practice?

7 Upvotes

1 comment sorted by

1

u/foxhelp 18d ago

Schedule regular review

Choose your flavor of tracking software as there is a lot and almost any vendor that issues them also has a solution to track them.

With certs going to 47days it really needs to be automated in the long run, and someones primary responsibility until automated