Once in use, who is responsible for fixing it if it's broken? That's the team 
that should manage them.

Usually.

Dave

-----Original Message-----
From: [email protected] [mailto:[email protected]] On 
Behalf Of Kurt Buff
Sent: Tuesday, July 05, 2016 7:50 PM
To: ntsysadm <[email protected]>
Subject: Re: [NTSysADM] Opinion / poll - Certificates - Infrastructure, or Apps?

In my world the infrastructure team (that is, a small environment, which also 
means it incorporates the security staff (that would be me, for whatever that's 
worth)) provides the server and the services running on it.

Web coders and business application stand up their apps in a dev/test, and 
provide documentation that the infrastructure team uses to create HA and DR 
plans, then the infrastructure/security team rolls it out to production when 
everything is deemed cooked and ready to go.

And this makes sense to me, because what are certs for, anyway?
They're a security measure, and implementing them belongs with the team 
responsible for security - just as implementing systems in production belongs 
with the infrastructure team, in partnership with the security team.

Kurt


On Tue, Jul 5, 2016 at 4:53 PM, Jack Kramer <[email protected]> wrote:
> The application owner should be responsible if you ask me. It’s an awfully 
> high burden to expect the cert management team to become familiar with every 
> application which may at some point require a SSL cert.
>
>
>> On Jul 5, 2016, at 6:50 PM, Jonathan Raper <[email protected]> wrote:
>>
>> Hi all,
>>
>> The subject line says it all. I'm trying to work out a point of delineation 
>> between our apps and infrastructure groups as to who owns what....I see 
>> certificates as a point of question....
>>
>> So, what do you all think? For those of you who deal with larger 
>> environments, who handles the certs? The application team or the 
>> Infrastructure team? I realize that there are exceptions to every rule, but 
>> I'm talking in generalities here. I'm not talking about the actual 
>> generation of the cert, but say you have an app group that has their own 
>> custom application, and they need a cert. Infrastructure procures it, and 
>> then hands it over to the apps team to install, or the infrastructure team 
>> asks where it needs to be installed and then installs it?
>>
>> Case in point - we had an app that broke today because the cert was not 
>> properly bound to the site in IIS. The Infrastructure team installed the 
>> cert to the servers in the proper store, and then alerted the apps team that 
>> it was there....apps team took no action, and did not communicate back that 
>> they took no action, and so then the infrastructure team took no action 
>> because the assumption was that it was an apps team responsibility once the 
>> cert was on the server.....but then the infrastructure team ended up fixing 
>> it in the end.
>>
>> Thanks,
>>
>> Jonathan
>> NOTE: This message and any attachments is intended solely for the use of the 
>> individual or entity to which it is addressed and may contain information 
>> that is non-public, proprietary, legally privileged, confidential, and/or 
>> exempt from disclosure. If you are not the intended recipient, you are 
>> hereby notified that any use, dissemination, distribution, or copying of 
>> this communication is strictly prohibited. If you have received this 
>> communication in error, please notify the original sender immediately by 
>> telephone or return email and destroy or delete this message along with any 
>> attachments immediately.
>>
>>
>


Attention: Information contained in this message and or attachments is intended 
only for the recipient(s) named above and may contain confidential and or 
privileged material that is protected under State or Federal law. If you are 
not the intended recipient, any disclosure, copying, distribution or action 
taken on it is prohibited. If you believe you have received this email in 
error, please contact the sender with a copy to [email protected], delete 
this email and destroy all copies.

Reply via email to