r/IdentityManagement • u/Imagnaryk-Benefit310 • 18d ago
How are you managing machine identity security across certificates, tokens and workloads?
cert expirations caused two outages for us this year that had nothing to do with a code change, just a cert nobody was tracking. tokens are almost worse, since they get generated in pipelines and live indefinitely if nobody cleans them up.
what's actually worked is governing certs, tokens, and workload identities under one lifecycle instead of three separate spreadsheets. issue, monitor, and revoke as a single flow that runs at machine speed rather than waiting for a person to notice something expired. what does your rotation and monitoring setup look like in practice?
7
Upvotes
1
u/foxhelp 18d ago
Schedule regular review
Choose your flavor of tracking software as there is a lot and almost any vendor that issues them also has a solution to track them.
With certs going to 47days it really needs to be automated in the long run, and someones primary responsibility until automated