Connector for private certificate authority and directory service
A method includes receiving, by a service operating in a provider network comprising a plurality of tenants, a request from a user device of one or more user devices in a user VPC of a first tenant of the plurality of tenants, wherein the request includes service identity information and authentication information. The method also includes providing, by the service, the request to an intermediary service operating in the provider network, wherein the intermediary service associates the service identity information with information maintained by the intermediary service associated with the tenants, and authenticating, by the intermediary service and with a domain controller, the request based on the authentication information. The method further includes, after the request is successfully authenticated, generating, by a private certificate authority (PCA) in a service VPC separate from the user VPC, a certificate based on the request, and providing the certificate to the user device.
1 . A method, comprising:
receiving, by a service operating in a provider network comprising a plurality of tenants, a request from a user device of one or more user devices in a user virtual private cloud (VPC) of a first tenant of the plurality of tenants, wherein the request includes service identity information and authentication information;
providing, by the service, the request to an intermediary service operating in the provider network, wherein the intermediary service associates the service identity information with information maintained by the intermediary service associated with the tenants;
authenticating, by the intermediary service and with a domain controller, the request based on the authentication information;
after the request is successfully authenticated, generating, by a private certificate authority (PCA) in a service VPC separate from the user VPC, a certificate based on the request; and
providing, by the service, the certificate to the user device.
2 . The method of claim 1 , further comprising, before receiving the request:
generating a private network connection between the service VPC and the user VPC based on private network credentials provided by the user device;
generating a domain controller connection between the intermediary service and the domain controller based on domain controller credentials stored by the intermediary service; and
providing, from the PCA to the domain controller, a certificate chain to establish trust between the PCA and the domain controller based on the certificate chain.
3 . The method of claim 1 , wherein the service VPC includes a plurality of intermediary services including the intermediary service, wherein each of the plurality of intermediary services is associated with a tenant including the user VPC.
4 . The method of claim 3 , further comprising, after receiving the request:
identifying, by the service, the intermediary service from the plurality of intermediary services based on the service identity information of the request.
5 . The method of claim 1 , wherein authenticating the request comprises:
generating a domain controller connection between the intermediary service and the domain controller via a proxy service; and
verifying, with the domain controller and via the proxy service, the authentication information of the request for authenticating the request.
6 . A system, comprising:
at least one compute node operating in a provider network, the compute node configured to perform operations comprising:
receiving, by a service device, a request from a user device of one or more user devices in a user virtual private cloud (VPC), the request including service identity information and authentication information;
providing, by the service device, the request to an intermediary service, the intermediary service associated with the service identity information;
authenticating, by the intermediary service and with a domain controller, the request based on the authentication information;
after the request is successfully authenticated, generating, by a private certificate authority (PCA), a certificate based on the request; and
providing, by the service device, the certificate to the user device.
7 . The system of claim 6 , wherein the intermediary service and the PCA are in a service VPC separate from the user VPC.
8 . The system of claim 7 , wherein the at least one compute node is configured to perform operations further comprising, before receiving the request:
generating a private network connection between the service VPC and the user VPC based on private network credentials provided by the user device;
generating a domain controller connection between the intermediary service and the domain controller based on domain controller credentials stored by the intermediary service; and
providing, from the PCA to the domain controller, a certificate chain to establish trust between the PCA and the domain controller based on the certificate chain.
9 . The system of claim 6 , wherein the service VPC includes a plurality of intermediary services including the intermediary service.
10 . The system of claim 9 , wherein the at least one compute node is configured to perform operations further comprising, after receiving the request:
identifying, by the service device, the intermediary service from the plurality of intermediary services based on the service identity information of the request.
11 . The system of claim 6 , wherein the service device comprises one or more of the intermediary service or the PCA.
12 . The system of claim 6 , wherein authenticating the request comprises:
generating a domain controller connection between the intermediary service and the domain controller via a proxy service; and
verifying, with the domain controller and via the proxy service, the authentication information of the request for authenticating the request.
13 . The system of claim 12 , wherein the proxy service and the domain controller are in the user VPC.
14 . A non-transitory computer-readable medium, comprising:
one or more instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
receiving a request from a user device of one or more user devices in a user virtual private cloud (VPC), the request including service identity information and authentication information;
providing the request to an intermediary service of a plurality of intermediary services, the intermediary service associated with the service identity information;
authenticating, using the intermediary service and with a domain controller, the request based on the authentication information;
after the request is successfully authenticated, generating, by a private certificate authority (PCA), a certificate based on the request; and
providing the certificate to the user device.
15 . The non-transitory computer-readable medium of claim 14 , wherein the one or more instructions cause the one or more processors to perform operations further comprising, before receiving the certificate request:
generating a private network connection between a service VPC and the user VPC based on private network credentials provided by the user device wherein the service VPC includes a plurality of intermediary services including the intermediary service;
generating a domain controller connection between the intermediary service and the domain controller based on domain controller credentials stored by the intermediary service; and
providing, from the PCA to the domain controller, a certificate chain to establish trust between the PCA and the domain controller based on the certificate chain.
16 . The non-transitory computer-readable medium of claim 14 , wherein the service VPC includes a plurality of intermediary services including the intermediary service.
17 . The non-transitory computer-readable medium of claim 16 , wherein the one or more instructions cause the one or more processors to perform operations further comprising, after receiving the request:
identifying the intermediary service from the plurality of intermediary services based on the service identity information of the request.
18 . The non-transitory computer-readable medium of claim 14 , wherein the intermediary service and the PCA are running on the same device.
19 . The non-transitory computer-readable medium of claim 14 , wherein authenticating the request comprises:
generating a domain controller connection between the intermediary service and the domain controller via a proxy service; and
verifying, with the domain controller and via the proxy service, the authentication information of the request for authenticating the request.
20 . The non-transitory computer-readable medium of claim 19 , wherein the proxy service and the domain controller are in the user VPC.