Operations About 1 min read

Certificate and account lifecycle

Maintain records for certificates, service accounts, operators and physical credentials. Assign owners, review triggers and removal processes for each.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.

Verification and testing

Overview#

Treat device certificates, workload identities, API credentials, operator accounts, physical credentials, vendor access and break glass access as separate inventories with linked owners and review triggers.

Lifecycle events#

Event Required actions
Join/install Verify identity, issue unique least privilege access, set expiry/review, record recovery owner
Move/change Recalculate roles, sites, door/device scope, tenant and support access; remove inherited permissions
Certificate renewal Validate name/key use, stage trust overlap, confirm time, deploy, verify, retire old trust
Suspected compromise Revoke/disable, contain sessions, rotate related material, inspect use, restore trusted identity
Leave/remove Disable promptly, revoke tokens/certificates/credentials, transfer ownership, preserve audit
Vendor engagement end Remove accounts, tunnels, API keys, certificates, cloud delegation and local exceptions
Decommission Destroy private keys/secrets and remove the asset from trust, directory, broker, cloud and recovery systems

Account rules#

  • Use named human accounts and unique service identities; prohibit shared daily administration.
  • Separate operator, administrator, installer, audit, export and high impact control roles.
  • Set service credentials to non interactive use and restrict origin/resource/action.
  • Review dormant, orphaned, default, local fallback, vendor and break glass identities.
  • Rotate without embedding secrets in integration source or documentation.
  • Monitor denied authentication, role changes, token issuance, certificate errors and use outside expected context.

Certificate register#

Record subject/service identity, issuer, serial/fingerprint, key usage, endpoints, trust anchors, issue/expiry, renewal method, owner, revocation mechanism, algorithm/profile, deployment status and dependent protocol. Alert early enough for change approval and staged rollout.

Sources#

Section overview · Wiki home