DevOps OffBoarding - SSL Certificate Issue
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ height:90px;width:728px;box-sizing:border-box;
}
A devops person setups a server, installs SSL cert and apps.
He/she would therefore have access to SSL cert and its private key.
How should he/she be off-boarded in a way so that SSL cert is not misused by him/her afterwards?
Should this be part of some contract or should the cert be renewed?
What is the best way such cases are handled in organizations?
ssl-certificate devops
add a comment |
A devops person setups a server, installs SSL cert and apps.
He/she would therefore have access to SSL cert and its private key.
How should he/she be off-boarded in a way so that SSL cert is not misused by him/her afterwards?
Should this be part of some contract or should the cert be renewed?
What is the best way such cases are handled in organizations?
ssl-certificate devops
add a comment |
A devops person setups a server, installs SSL cert and apps.
He/she would therefore have access to SSL cert and its private key.
How should he/she be off-boarded in a way so that SSL cert is not misused by him/her afterwards?
Should this be part of some contract or should the cert be renewed?
What is the best way such cases are handled in organizations?
ssl-certificate devops
A devops person setups a server, installs SSL cert and apps.
He/she would therefore have access to SSL cert and its private key.
How should he/she be off-boarded in a way so that SSL cert is not misused by him/her afterwards?
Should this be part of some contract or should the cert be renewed?
What is the best way such cases are handled in organizations?
ssl-certificate devops
ssl-certificate devops
asked Nov 22 '18 at 13:22
Lalit BhattLalit Bhatt
457
457
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
would like to share my candid response in a manner that I deem fit. These are just my personal views.
A DevOps engineer is an integral part of any technology company, which is nurtured with trust and longevity. In terms of safety & security, they know all the weaknesses of the Development team (code) - and possible ways it can compromise the system. SSL is a very tiny piece in the big picture. One should be concerned for N number of other possible vulnerabilities in their system.
Every DevOps engineer chose to be one - because they love how cloud computing and the complexity of a secure network. They religiously ensure security & safety of the entire system 24X7 - in their best capacity. We value associations over petty money/disputes - and we lead an ethical life and not just act ethically on the work front. To add to this - I being one myself - I know how much effort, hard work, dedication and most importantly Time is required to gain client’s trust - I would never imagine throwing all my life work, just like that.
Coming back to a possible solution to your problem - pick up a team or an individual whom you TRUST - ask them to revisit the entire network and secure any vulnerabilities, if any. Changing the SSL would be recommended along with resetting all the passwords.
add a comment |
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53431959%2fdevops-offboarding-ssl-certificate-issue%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
would like to share my candid response in a manner that I deem fit. These are just my personal views.
A DevOps engineer is an integral part of any technology company, which is nurtured with trust and longevity. In terms of safety & security, they know all the weaknesses of the Development team (code) - and possible ways it can compromise the system. SSL is a very tiny piece in the big picture. One should be concerned for N number of other possible vulnerabilities in their system.
Every DevOps engineer chose to be one - because they love how cloud computing and the complexity of a secure network. They religiously ensure security & safety of the entire system 24X7 - in their best capacity. We value associations over petty money/disputes - and we lead an ethical life and not just act ethically on the work front. To add to this - I being one myself - I know how much effort, hard work, dedication and most importantly Time is required to gain client’s trust - I would never imagine throwing all my life work, just like that.
Coming back to a possible solution to your problem - pick up a team or an individual whom you TRUST - ask them to revisit the entire network and secure any vulnerabilities, if any. Changing the SSL would be recommended along with resetting all the passwords.
add a comment |
would like to share my candid response in a manner that I deem fit. These are just my personal views.
A DevOps engineer is an integral part of any technology company, which is nurtured with trust and longevity. In terms of safety & security, they know all the weaknesses of the Development team (code) - and possible ways it can compromise the system. SSL is a very tiny piece in the big picture. One should be concerned for N number of other possible vulnerabilities in their system.
Every DevOps engineer chose to be one - because they love how cloud computing and the complexity of a secure network. They religiously ensure security & safety of the entire system 24X7 - in their best capacity. We value associations over petty money/disputes - and we lead an ethical life and not just act ethically on the work front. To add to this - I being one myself - I know how much effort, hard work, dedication and most importantly Time is required to gain client’s trust - I would never imagine throwing all my life work, just like that.
Coming back to a possible solution to your problem - pick up a team or an individual whom you TRUST - ask them to revisit the entire network and secure any vulnerabilities, if any. Changing the SSL would be recommended along with resetting all the passwords.
add a comment |
would like to share my candid response in a manner that I deem fit. These are just my personal views.
A DevOps engineer is an integral part of any technology company, which is nurtured with trust and longevity. In terms of safety & security, they know all the weaknesses of the Development team (code) - and possible ways it can compromise the system. SSL is a very tiny piece in the big picture. One should be concerned for N number of other possible vulnerabilities in their system.
Every DevOps engineer chose to be one - because they love how cloud computing and the complexity of a secure network. They religiously ensure security & safety of the entire system 24X7 - in their best capacity. We value associations over petty money/disputes - and we lead an ethical life and not just act ethically on the work front. To add to this - I being one myself - I know how much effort, hard work, dedication and most importantly Time is required to gain client’s trust - I would never imagine throwing all my life work, just like that.
Coming back to a possible solution to your problem - pick up a team or an individual whom you TRUST - ask them to revisit the entire network and secure any vulnerabilities, if any. Changing the SSL would be recommended along with resetting all the passwords.
would like to share my candid response in a manner that I deem fit. These are just my personal views.
A DevOps engineer is an integral part of any technology company, which is nurtured with trust and longevity. In terms of safety & security, they know all the weaknesses of the Development team (code) - and possible ways it can compromise the system. SSL is a very tiny piece in the big picture. One should be concerned for N number of other possible vulnerabilities in their system.
Every DevOps engineer chose to be one - because they love how cloud computing and the complexity of a secure network. They religiously ensure security & safety of the entire system 24X7 - in their best capacity. We value associations over petty money/disputes - and we lead an ethical life and not just act ethically on the work front. To add to this - I being one myself - I know how much effort, hard work, dedication and most importantly Time is required to gain client’s trust - I would never imagine throwing all my life work, just like that.
Coming back to a possible solution to your problem - pick up a team or an individual whom you TRUST - ask them to revisit the entire network and secure any vulnerabilities, if any. Changing the SSL would be recommended along with resetting all the passwords.
answered Nov 23 '18 at 8:48
AnmolNagpalAnmolNagpal
1337
1337
add a comment |
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53431959%2fdevops-offboarding-ssl-certificate-issue%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown