Certificate and account lifecycle
Maintain records for certificates, service accounts, operators and physical credentials. Assign owners, review triggers and removal processes for each.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Research and static guidance only; product and deployment specific behaviour requires controlled environment validation and authoritative product evidence.
On this page
Overview#
Treat device certificates, workload identities, API credentials, operator accounts, physical credentials, vendor access and break glass access as separate inventories with linked owners and review triggers.
Lifecycle events#
| Event | Required actions |
|---|---|
| Join/install | Verify identity, issue unique least privilege access, set expiry/review, record recovery owner |
| Move/change | Recalculate roles, sites, door/device scope, tenant and support access; remove inherited permissions |
| Certificate renewal | Validate name/key use, stage trust overlap, confirm time, deploy, verify, retire old trust |
| Suspected compromise | Revoke/disable, contain sessions, rotate related material, inspect use, restore trusted identity |
| Leave/remove | Disable promptly, revoke tokens/certificates/credentials, transfer ownership, preserve audit |
| Vendor engagement end | Remove accounts, tunnels, API keys, certificates, cloud delegation and local exceptions |
| Decommission | Destroy private keys/secrets and remove the asset from trust, directory, broker, cloud and recovery systems |
Account rules#
- Use named human accounts and unique service identities; prohibit shared daily administration.
- Separate operator, administrator, installer, audit, export and high impact control roles.
- Set service credentials to non interactive use and restrict origin/resource/action.
- Review dormant, orphaned, default, local fallback, vendor and break glass identities.
- Rotate without embedding secrets in integration source or documentation.
- Monitor denied authentication, role changes, token issuance, certificate errors and use outside expected context.
Certificate register#
Record subject/service identity, issuer, serial/fingerprint, key usage, endpoints, trust anchors, issue/expiry, renewal method, owner, revocation mechanism, algorithm/profile, deployment status and dependent protocol. Alert early enough for change approval and staged rollout.
Sources#
- NIST 800 63, NIST SP 800-63-4 Digital Identity Guidelines, accessed 25 August 2026.
- NIST 800 57, NIST SP 800-57 Part 1 Rev. 5: Key Management, accessed 25 August 2026.