Entrust Nshield Hsms and Mirantis Kubernetes Engine Enhance The
Total Page:16
File Type:pdf, Size:1020Kb
Entrust nShield HSMs and Mirantis Kubernetes Engine Enhance the Security of Containerized Applications Integrated solution enables application developers to easily access high assurance cryptographic services HIGHLIGHTS THE PROBLEM • Support today’s fast-paced application Developers lack ability to access container deployment environments cryptographic functions for their • Provide secure access to Entrust applications nShield® hardware security modules Modern application development uses (HSMs) containers and Kubernetes to standardize • Allow critical cryptographic key software design and facilitate continuous management to run transparently integration and continuous delivery (CI/CD). • Establish a FIPS 140-2 and Common The process enables developers to deploy Criteria certified root of trust new applications with the assurance that they’ll run reliably in any user environment. • Help facilitate auditing and compliance A critical component of the software with data security regulations development process is the security of the CI/CD software supply chain. To date, adding an HSM root of trust for container deployments has been difficult. LEARN MORE AT ENTRUST.COM Enhancing the security of containerized applications THE CHALLENGE THE SOLUTION Enabling access to cryptographic Mirantis Kubernetes Engine services without impacting and Entrust nShield HSMs development process Mirantis Kubernetes Engine is a market- While the security of applications developed leading container platform for accelerating using containers and Kubernetes is critically the development and delivery of modern important, it’s also essential to maintain the applications. The platform provides accelerated pace that these technologies developer choice, simple onboarding, and offer. Robust cryptographic services – automation across DevOps. It also enables a including key creation, signing, verification, secure pipeline to Kubernetes environments and encryption – need to integrate with the that run anywhere without losing software development process easily and operational flexibility and agility. Mirantis transparently. Kubernetes Engine provides: Solutions that enable this integration not • Consistent Kubernetes clusters: only protect the integrity of applications, Deploy with Mirantis Kubernetes but also of the data they process, helping Engine across bare metal, private facilitate security auditing and regulatory clouds, and public clouds; simplifies compliance. creation of CI/CD and automation that works everywhere • Docker trusted registry: A private container registry with external registration mirroring, image security scanning, signing, and promotion policies; lets you quickly identify and mitigate vulnerabilities in curated images • Docker content trust: Strict policy management preventing execution of inappropriately signed images; ensures process and oversight compliance in preparing workloads for test, staging, and production • FIPS-140-2 certified encryption and DISA STIG compliance Integration of Mirantis Kubernetes Engine with Entrust nShield Container Option Pack gives application developers the ability to access the cryptographic functionality of a robust, industry-leading nShield HSM within a container-based environment. LEARN MORE AT ENTRUST.COM Enhancing the security of containerized applications HOW IT WORKS Cryptographice Services nShield Security nShield Container Option Pack (encrypt, decrypt, sign, World Software verify, key generation) Build Image Developer nShield HSMs or Core OS nShield as a Service Applications to be Mirantis Kubernetes Engine containerized Key Stage 1: Building containerized images Kubernetes (orchesteration) Container Core OS images Stage 2: Operations Mirantis Kubernetes Engine streamlines the application development process 1. Developers build containerized images using the Entrust nShield Security World software and the nShield Container Option Pack. 2. The Mirantis Kubernetes Engine provides the tools to test and deploy the containerized applications, abstracting the complexities of the Kubernetes layer. 3. Cryptographic services including encryption, decryption, signing, verification, and underpinning key generation are enabled using Entrust nShield HSMs on premises or nShield as a Service. 4. Containerized images with high assurance cryptographic functions can be built in a flexible and scalable manner. LEARN MORE AT ENTRUST.COM A CLOSER LOOK Why use nShield HSMs with Mirantis Kubernetes Engine? About Entrust nShield HSMs Entrust nShield HSMs are specifically designed Entrust nShield HSMs are among the to safeguard and manage cryptographic highest-performing, most secure, and keys and processes within a certified easiest-to-integrate HSMs available. hardware environment to establish a root They help facilitate regulatory of trust. Critical keys handled outside the compliance and deliver the highest cryptographic boundary of a certified HSM are levels of data and application significantly more vulnerable to attacks that security for enterprise, financial, can compromise confidential information. and government organizations. Our unique Security World key Entrust nShield HSMs, offered as an appliance management architecture provides deployed at an on-premises datacenter or strong, granular controls over access leased through an as-a-service subscription, and usage of keys. provide enhanced key generation, signing, and encryption to protect sensitive container data For more information visit and transactions. Using HSMs as part of an entrust.com/HSM. enterprise encryption and/or key management strategy is considered a best practice among About Mirantis cybersecuity professionals. Mirantis helps organizations ship code Entrust nShield HSMs provide a hardened, faster on public and private clouds. tamper-resistant environment for performing Mirantis Kubernetes Engine provides secure cryptographic processing, key one cohesive cloud experience for protection, and key management. delivering consistent Kubernetes anywhere, providing a single pane of glass for metrics, and fully Why nShield Container Option Pack automated lifecycle management with continuous updates. for Mirantis Kubernetes Engine? Open-source Lens, the leading Entrust nShield Container Option Pack Kubernetes IDE (sponsored by provides a set of scripts for seamless Mirantis), complements Container development and deployment of containerized Cloud by providing unique insights into applications, underpinned by a high objects and containers across a fleet assurance Entrust nShield HSM. For DevOps of clusters, dramatically simplifying and DevSecOps, Entrust nShield Container Kubernetes complexity. Mirantis serves Option Pack provides the tools and proven leading global enterprises, including architecture to deploy containers at scale as Adobe, DocuSign, Liberty Mutual, part of a CI/CD process. When the time from Nationwide Insurance, PayPal, development to deployment is tight, Entrust and Splunk. nShield Container Option Pack accelerates the development of container images with For more information visit cryptography provisioned by an Entrust mirantis.com nShield HSM root of trust. Learn more at entrust.com Entrust, nShield, and the Hexagon logo trademarks, registered trademarks, and/or service marks of Entrust Corporation in the U.S. and/or other countries. All other brand or product names are the property of their U.S. Toll-Free Phone: 888 690 2424 respective owners. Because we are continuously improving our products and services, Entrust Corporation International Phone: +1 952 933 1223 reserves the right to change specifications without prior notice. Entrust is an equal opportunity employer. © 2020 Entrust Corporation. HS21Q3-hsm-mirantis-kubernetes-container-ss [email protected].