Establishing a trust relationship in a hybrid cloud management and management service environment
A system can receive, by a cloud management platform, a request from a user account for a trust certificate. The system can provide, to the user account via a first pathway, the trust certificate, comprising a first portion of a secret. The system can provide, to the user account via a second pathway, a second portion of the secret. The system can receive, at an on-premises cloud controller (OPCC), data indicative of the first and second portions. The system can, in response to the OPCC validating the first secret, receive, by the cloud management platform and from the OPCC, a second request to instantiate a trust relationship, wherein the second request comprises a first message body that is signed and encrypted with the first secret. The system can send, by the cloud management platform and to the OPCC, a message that comprises a second trust certificate and a second secret.
1. A system for establishing a trust relationship in a cloud environment, comprising:
a processor device; and
a memory that stores executable instructions that, when executed by the processor device, facilitate performance of operations, comprising:
receiving, by a cloud management platform of the system, a first request from a user account for a first trust certificate, wherein the cloud management platform is configured to provide a hybrid cloud management functionality that comprises a service management datacenter, a customer datacenter for a customer, public cloud resources for the customer, and a colocation datacenter;
providing, to the user account by the cloud management platform via a first pathway, a first capability to access the first trust certificate, wherein the first trust certificate comprises a first portion of a first secret;
providing, to the user account by the cloud management platform via a second pathway, a second capability to access a second portion of the first secret;
receiving, at an on-premises cloud controller (OPCC) at the customer datacenter, user input data indicative of the first portion of the first secret and the second portion of the first secret;
in response to the OPCC validating the first secret, receiving, by the cloud management platform and from the OPCC, a second request to instantiate a trust relationship, wherein the second request comprises a first message body that is signed and encrypted with the first secret;
sending, by the cloud management platform and to the OPCC, a message that comprises a second trust certificate and a second secret, and wherein the message comprises a second message body that is signed and encrypted with the first secret; and
communicating, by the cloud management platform, with the OPCC using the second trust certificate and the second secret to validate communications.
2. The system of claim 1 , wherein the operations further comprise:
validating a user credential of the user account and a subscription of the user account before providing the first capability to access the first trust certificate to the user account via the first pathway.
3. The system of claim 1 , wherein the first pathway comprises a download of the first trust certificate from an interface via which the first request is made.
4. The system of claim 1 , wherein providing the second capability to access the second portion of the first secret to the user account via the second pathway comprises sending the second portion of the first secret to an email address associated with the user account.
5. The system of claim 1 , wherein the OPCC validating the first trust certificate comprises using a product subject root certificate in a trust store of the OPCC.
6. The system of claim 1 , wherein the second request is signed and encrypted using the first secret by the OPCC.
7. The system of claim 6 , wherein the operations further comprise:
decrypting the second request using the first secret.
8. A method for establishing a trust relationship in a cloud environment, comprising:
receiving, by a system comprising a processor, a first request from a user account for a first trust certificate;
providing, by the system via a first pathway, the first trust certificate to the user account, wherein the first trust certificate comprises a first portion of a first secret;
providing, by the system via a second pathway, a second portion of the first secret to the user account;
receiving, at an on-premises cloud controller (OPCC) of the system, user input data indicative of the first portion of the first secret and the second portion of the first secret;
in response to the OPCC validating the first trust certificate, receiving, by the system and from the OPCC, the second request to instantiate a trust relationship, wherein the second request comprises a message body that is signed and encrypted with the first portion and the second portion of the first secret of the received user input data;
sending, by the system and to the OPCC, a second trust certificate and a second secret; and
communicating, by the system, with the OPCC using the second trust certificate and the second secret to validate communications according to the trust relationship.
9. The method of claim 8 , wherein the second request is signed with a hash-based message authentication code by the OPCC using a hash key derived from the first secret.
10. The method of claim 9 , further comprising:
validating, by the system, an integrity of the second request by verifying a signature of the hash-based message authentication code.
11. The method of claim 8 , wherein the second request comprises OPCC attestation data for validation.
12. The method of claim 11 , further comprising:
validating, by the system, authenticity and integrity of the OPCC by verifying the OPCC attestation data.
13. The method of claim 8 , further comprising:
authorizing, by a policy engine of the system, the OPCC based on a third request by a trust engine of the system.
14. The method of claim 13 , wherein the policy engine validates that the user account provided the first secret as part of the second request, and wherein the policy engine validates that the user account is associated with the OPCC.
15. A non-transitory computer-readable medium comprising instructions for establishing a trust relationship in a cloud environment that, in response to execution, cause a system comprising a processor to perform operations, comprising:
receiving, by a first computing device of the system, a first request from a user account for a first trust certificate;
enabling, by the first computing device, access to the first trust certificate for the user account in multiple parts via respective different pathways, wherein the first trust certificate comprises a first secret;
receiving, by a second computing device of the system, user input data indicative of the multiple parts of the first secret, to produce received multiple parts of the first secret;
in response to the second computing device having validated the first trust certificate and the user input data, receiving, by the first computing device and sent from the second computing device, a second request to instantiate a trust relationship, wherein the second request comprises a message body that is signed and encrypted with the received multiple parts of the first secret;
sending, by the first computing device and to the second computing device, a second trust certificate and a second secret; and
communicating, by the first computing device, with the second computing device using the second trust certificate and the second secret to secure communications.
16. The non-transitory computer-readable medium of claim 15 , wherein a trust engine of first computing device sends, to the second computing device, the second trust certificate in response to receiving authorization from a policy engine of the first computing device.
17. The non-transitory computer-readable medium of claim 15 , wherein the trust engine issues the second trust certificate and the second secret.
18. The non-transitory computer-readable medium of claim 15 , wherein the second trust certificate and the second secret are encrypted with the first secret for any communications sent to the second computing device.
19. The non-transitory computer-readable medium of claim 15 , wherein the second computing device discards the first secret after communicating with the first computing device using the second trust certificate and the second secret.
20. The non-transitory computer-readable medium of claim 15 , wherein the second computing device disables the first trust certificate after communicating with the first computing device using the second trust certificate and the second secret.