---
title: "Automated Internal PKI with Ephemeral X.509 Certificates | Zero-Trust Architecture Canon"
description: "Dynamic certificate authority architecture utilizing HashiCorp Vault PKI Secrets Engine, automatically issuing sub-hour ephemeral X.509 and SSH certificates with automated zero-touch rotation."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/pki-vault-short-lived-certs"
locale: "en"
---

# Automated Internal PKI with Ephemeral X.509 Certificates (`zt-arch-14`)

> **Pillar**: IDENTITY | **Archetype**: IDENTITY_ATTESTATION
> **Blocked MITRE ATT&CK Techniques**: T1552.004, T1098.004, T1021.004

## Architecture Summary

Dynamic certificate authority architecture utilizing HashiCorp Vault PKI Secrets Engine, automatically issuing sub-hour ephemeral X.509 and SSH certificates with automated zero-touch rotation.

## Adversary Model

Adversary exfiltrates internal TLS private key or SSH key, attempting to maintain persistent long-term access.

## NIST SP 800-207 Core Tenets

- Access to individual enterprise resources is granted on a per-session basis.
- All communication is secured regardless of network location.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: Vault PKI issuing 30-day internal TLS certificates for microservices.
- **Authentication Enforcement**: Vault AppRole authentication from Kubernetes deployment secrets.
- **Network Isolation**: Vault accessible over private VPC network.

### ADVANCED Maturity Target

- **Implementation Scope**: Sub-hour ephemeral certificates (TTL 60 min) managed via cert-manager Vault issuer.
- **Authentication Enforcement**: Kubernetes Service Account JWT authentication with automatic identity binding.
- **Network Isolation**: Mutual TLS enforced between cert-manager and Vault cluster.

### OPTIMAL Maturity Target

- **Implementation Scope**: Multi-datacenter Vault replication with automated CRL generation and short-lived SSH client certs.
- **Authentication Enforcement**: Sub-15-minute certificates; zero persistent private keys stored on disks anywhere.
- **Network Isolation**: Hardware Security Module (HSM) rooted offline Root CA with automated intermediate generation.

## Terraform HCL Manifest

```hcl
resource "vault_mount" "pki" {
  path        = "pki_int"
  type        = "pki"
  description = "TinyCTO Ephemeral Intermediate PKI"
  default_lease_ttl_seconds = 3600
  max_lease_ttl_seconds     = 86400
}

resource "vault_pki_secret_backend_role" "role" {
  backend          = vault_mount.pki.path
  name             = "tinycto-microservices"
  ttl              = 3600
  allow_ip_sans    = true
  key_type         = "ed25519"
  allowed_domains  = ["internal.tinycto.tv"]
  allow_subdomains = true
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: order-service-tls
  namespace: production
spec:
  secretName: order-service-tls
  duration: 1h
  renewBefore: 15m
  issuerRef:
    name: vault-issuer
    kind: ClusterIssuer
  commonName: order-service.internal.tinycto.tv
  dnsNames:
  - order-service.internal.tinycto.tv
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Automated Internal PKI with Ephemeral X.509 Certificates | Zero-Trust Architecture Canon",
  "description": "Dynamic certificate authority architecture utilizing HashiCorp Vault PKI Secrets Engine, automatically issuing sub-hour ephemeral X.509 and SSH certificates with automated zero-touch rotation.",
  "url": "https://tinycto.tv/zero-trust/architectures/pki-vault-short-lived-certs"
}
```
