Rotate keys more frequently

Get ready to have to login all the fucking time:

Access and identity tokens should be valid for no more than an hour, the report says, and expired tokens must be rejected outright by authorization services and policy enforcement points.

On key management, signing keys for high-impact systems should be rotated at least every 90 days, and within a year everywhere else. At moderate impact and above they must sit in hardware-backed or isolated storage, never persistently on the servers, virtual machines or containers using them. High-impact systems must also sign inside an isolated execution environment.

🔗 CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

Comments

Leave a Reply

Categories:

Discover more from Coté

Subscribe now to keep reading and get access to the full archive.

Continue reading