A Global Financial Institution Re-gains Control of Trusted Access
An audit revealed that developers used SSH keys to bypass existing privileged access management controls.
Customer
-
A global financial brand associated with trust and prosperity
-
35000+ managed hosts
-
Unix and Linux operating systems in various versions
-
Servers with both agents and agentless SSH management solutions
Challenge: An internal security audit revealed PAM bypass
The customer had three main drivers:
The need to conform to corporate security policies after a failed internal audit.
Developers were able to self-provision and use SSH keys to bypass existing privileged access management (PAM) security controls across production systems. Regaining control over SSH keys became a priority.
They needed to ensure their readiness for future audits and compliance with regulations.
Solution: Off-the-shelf complete SSH key lifecycle management
The corporate IT environment bears all the typical characteristics of the market – large server volumes, heterogeneous platforms, wide software and vendor diversity. These characteristics formulate the requirements for strict SSH key management – in line with existing operations and processes with risk- free and non-disruptive roll-out.
At first, the customer considered an in-house software development project. However, the complexity of the effort as well as the identified shortcomings in subject-matter expertise quickly turned their attention to us at SSH Communications Security, the original inventor of the SSH protocol and the world’s leading source of SSH expertise.
Our PrivX Key Manager addressed the customer's SSH key management issues with a purpose-built solution that focuses on workflows for SSH key management, as opposed to some competing solutions that are based on certificate management systems retrofitted for SSH keys.
Additionally, the product offering was completed with an extensive service and consultation package that ensured the smooth progress of the deployment project.
Benefits
Discover
PrivX Key Manager discovers and maps all SSH trust relationships and identifies unused, unmanaged, or unauthorized access. It also creates an inventory of such trusts as well as cryptographic assets.
Audit & comply
Define and implement SSH key policies, including length, expiration, and approved usage types. PrivX Key Manager tracks when and how keys are used - you receive alerts when keys are added, removed, modified, or unauthorized changes are made to SSH configurations.
Remediate
Identify and remove unused, duplicate, and non-compliant SSH keys through a secure automated workflow. Or update authorizations and renew old and non-compliant keys.
Manage & automate
A complete view of every SSH key in the environment, including who accessed what, when, and how. Automate SSH key creation, rotation, approval, and retirement within a secure, policy-driven workflow. All from a single central management platform.
Migrate to keyless SSH access
PrivX Key Manager offers a structured path to just-in-time, certificate-based SSH access - from managing static credentials to centrally controlled, certificate-based, keyless access. No need to vault the private keys first, no need to edit scripts, no need to edit applications.
