This enables Tanzu users to integrate their service mesh with a trusted certificate authority (CA) of their choice to support mutual Transport Layer Security (mTLS) between Kubernetes clusters, with automated management of their machine identity lifecycles.
Capabilities include the automated issuance and renewal of machine identities via Venafi's control plane; the generation of identities from over 40 trusted certificate authorities within the organisation's trust chain instead of relying on self-signed mTLS identities; and observability, consistency, reliability and freedom of choice over machine identity management, ensuring compliance with regulations.
"We are thrilled about the integration with Venafi, enabling our customers to use Tanzu Service Mesh in their own enterprise CA trust chain and use their own registry system," said VMware vice president and CTO Pere Monclus.
|
Venafi vice president of security strategy and threat intelligence Kevin Bocek said "It's exciting to see VMware simplify customers' cloud native journey, while still ensuring enterprise-grade security.
"Other service mesh – such as Istio – only support self-signed machine identities out-of-the-box, which fall outside of companies' existing machine identity management infrastructure and trust chains.
"It's great to see VMWare is addressing this security gap by tapping into the control plane for machine identity management in a way that's frictionless and security-team approved."