BFP-I-657: ACME methods for certificates: Document use thereof

BFP-I-657: ACME methods for certificates: Document use thereof

Given both the drawdown of certificate lifetimes, and BigFix's support of BYO-CA, many organizations are looking to the ACME protocol for automation of certificate renewals. BigFix should prepare content to help customers meet these goals. Some BigFix components are relatively simple -- client setttings of paths/files, and copying the right files to the right place. Others are more complex, but already have middleware components that support ACME.

This ask is for BigFix to:

  1. Document the use models of ACME for each BigFix component.
  2. Where appropriate, provide content that assists in this deployment.
  3. Where appropriate, document the use of already-present features that support ACME.
  4. Validate that, should the customer deploy any of the above, their use and settings are "safe", and will not be overwritten with future product updates.

An incomplete assessment of BigFix components follows:

These components are of the "copy files, restart services" variety.

  • Root server
  • Web Reports
  • WebUI

These use java and the OpenLiberty / WLP (WebSphere Liberty Profile) server. WLP seems to have native feature support for <feature>acmeCA-2.0</feature>.

  • Inventory
  • Compliance
  • Remote Control
2 Likes