Policy Enforcement for Secure ServiceMesh
To enable mTLS certificate issuance for application workloads from your Enterprise PKI, the PKI policies should be defined and enforced for your Service Mesh deployment.
The process for defining and enforcing the policy definition for your service mesh deployment is as follows.
-
CA Integration - Integrate AppViewX KUBE+ with your Internal CA for signing the certificates for your service mesh workloads.
-
CA Policy - Define CA Policy to enforce your organization crypto standards and map them to Certificate Groups ( to categorize certificates based on business units).
-
Enforce Cluster Policy - Enforce dedicated CA Policy / PKI policy to one more cluster to promote secure and compliant certificate management practices.