Enabling AppViewX Signer
2 Steps to Enable the Zero Trust Security for Containers Using mTLS Certificates
-
Enforce PKI policies to ensure the use of compliant CAs and strong
crypto-standards in your service mesh configuration.
-
Enable External CA signing mode for your Service Mesh configuration to sign
workloads with mTLS certificates from your Enterprise PKI.
Enabling a Signer for mTLS Certificate Issuance
- Onboard Cluster - Deploy / enable AppViewX Signer as a part of the KUBE+ component (cert-orchestrator).
- Policy Enforcement - Define and enforce CA and Cluster Policy
- Onboard Mesh - Configure CSR signing mode and the Certificate Authority to be used in Service Mesh.
- Enable External CA Mode - Configure Service Mesh to External CA mode for CSR signing.
Onboarding a Cluster
Onboarding a New Cluster
Note: While generating the
deployment configuration select the Feature gate Enable mTLS Certificates
for Service Mesh which enables AppViewX Signer as a part of the
deployment.
Onboarding an Existing Cluster
Note: While generating the modifying the deployment
configuration select the Feature gate Enable mTLS Certificates for
Service Mesh which enables AppViewX Signer as a part of the
deployment.
Policy Enforcement for Secure ServiceMesh
Defining and Enforcing the Policy Definition for your Service Mesh Deployment
- CA Integration - Integrate AppViewX KUBE+ with your Internal CA for signing the certificates for your service mesh workloads.
- CA Policy - Define CA Policy to enforce your organization crypto standards and map them to Certificate Groups ( to categorize certificates based on business units).
- Enforce Cluster Policy - Enforce dedicated CA Policy / PKI policy to one more cluster to promote secure and compliant certificate management practices.
CA Integration
AppViewX supports integrating with EJBCA and Microsoft CA for signing the mTLS service mesh workloads. Refer CA Integration for the steps on how to configure AppViewX KUBE+ with the respective Certificate Authority.
CA Policy
Cluster Policy
Note: For Service Mesh
External CA signing the policy type must be set to CA Setting
Cluster and the certificate authorities supported are EJBCA
and Microsoft CA.
