Certificates
Overview of certificate types available on Global Infra
Different kinds of certificates can be generated on GI depending on the usage and integration needed.
Public Certificates
Certificates signed by a public root CA, managed through the GI Pubcert service.
See the SSL Certificate service for details.
Vault Custom PKI
Each tenant can manage its own PKI and issue certificates using HashiCorp Vault. This is provided as part of the Vault shared service.
Puppet-Generated Certificates (autosec)
A Puppet function to generate certificates for communication in (mutual) TLS between applications.
Puppet-Managed Certificates (Windows)
Windows certificate store management is handled through Puppet configuration.
Internal Puppet PKI
Puppet manages its own PKI for communication between Puppet agents and servers. This is a GI internal service only.
Internal PKI
Used internally by GI, notably for container certificate management.