Skip to content

A Global Financial Institution Re-gains Control of Trusted Access

An audit revealed that developers used SSH keys to bypass existing privileged access management controls.

financial_institution

Customer

  • A global financial brand associated with trust and prosperity

  • 35000+ managed hosts

  • Unix and Linux operating systems in various versions

  • Servers with both agents and agentless SSH management solutions 

Powerful quantum-safe security solutions

Challenge: An internal security audit revealed PAM bypass

The customer had three main drivers:

The need to conform to corporate security policies after a failed internal audit.

Developers were able to self-provision and use SSH keys to bypass existing privileged access management (PAM) security controls across production systems. Regaining control over SSH keys became a priority.

They needed to ensure their readiness for future audits and compliance with regulations.

Solution: Off-the-shelf complete SSH key lifecycle management

The corporate IT environment bears all the typical characteristics of the market – large server volumes, heterogeneous platforms, wide software and vendor diversity. These characteristics formulate the requirements for strict SSH key management – in line with existing operations and processes with risk- free and non-disruptive roll-out.

At first, the customer considered an in-house software development project. However, the complexity of the effort as well as the identified shortcomings in subject-matter expertise quickly turned their attention to us at SSH Communications Security, the original inventor of the SSH protocol and the world’s leading source of SSH expertise.

Our PrivX Key Manager addressed the customer's SSH key management issues with a purpose-built solution that focuses on workflows for SSH key management, as opposed to some competing solutions that are based on certificate management systems retrofitted for SSH keys.

PrivX Key Manager handles the entire trusted access lifecycle - it discovers all SSH trust relationships, monitors SSH key usage, remediates access to conform to policies, and manages SSH-based access centrally. Like this, the bank regained full access control in their critical infrastructure.

Additionally, the product offering was completed with an extensive service and consultation package that ensured the smooth progress of the deployment project.

Benefits

key-skeleton

Discover

PrivX Key Manager discovers and maps all SSH trust relationships and identifies unused, unmanaged, or unauthorized access. It also creates an inventory of such trusts as well as cryptographic assets.

Certification

Audit & comply

Define and implement SSH key policies, including length, expiration, and approved usage types. PrivX Key Manager tracks when and how keys are used - you receive alerts when keys are added, removed, modified, or unauthorized changes are made to SSH configurations.

Priviledged-access-management

Remediate

Identify and remove unused, duplicate, and non-compliant SSH keys through a secure automated workflow. Or update authorizations and renew old and non-compliant keys.

gear-cycle

Manage & automate

A complete view of every SSH key in the environment, including who accessed what, when, and how. Automate SSH key creation, rotation, approval, and retirement within a secure, policy-driven workflow. All from a single central management platform.

Shield

Migrate to keyless SSH access

PrivX Key Manager offers a structured path to just-in-time, certificate-based SSH access - from managing static credentials to centrally controlled, certificate-based, keyless access. No need to vault the private keys first, no need to edit scripts, no need to edit applications.

 

Learn more about securing access of human and non-human identities with keyless SSH access.