This content has been machine translated dynamically.
Dieser Inhalt ist eine maschinelle Übersetzung, die dynamisch erstellt wurde. (Haftungsausschluss)
Cet article a été traduit automatiquement de manière dynamique. (Clause de non responsabilité)
Este artículo lo ha traducido una máquina de forma dinámica. (Aviso legal)
此内容已经过机器动态翻译。 放弃
このコンテンツは動的に機械翻訳されています。免責事項
이 콘텐츠는 동적으로 기계 번역되었습니다. 책임 부인
Este texto foi traduzido automaticamente. (Aviso legal)
Questo contenuto è stato tradotto dinamicamente con traduzione automatica.(Esclusione di responsabilità))
This article has been machine translated.
Dieser Artikel wurde maschinell übersetzt. (Haftungsausschluss)
Ce article a été traduit automatiquement. (Clause de non responsabilité)
Este artículo ha sido traducido automáticamente. (Aviso legal)
この記事は機械翻訳されています.免責事項
이 기사는 기계 번역되었습니다.책임 부인
Este artigo foi traduzido automaticamente.(Aviso legal)
这篇文章已经过机器翻译.放弃
Questo articolo è stato tradotto automaticamente.(Esclusione di responsabilità))
Translation failed!
Cryptography
The cryptographic algorithms Citrix SecurSpaces™ uses, and where each one applies. This page supports network security review and third-party assessment.
Data in transit
| Traffic | Protection |
|---|---|
| Browser and API traffic from outside the cluster | HTTPS. TLS is terminated at the ingress controller. |
| Ingress controller to SecurSpaces services | TLS |
| SecurSpaces service to SecurSpaces service | TLS |
| Remote development sessions | SSH |
Note:
Because TLS is terminated at the ingress controller, the permitted TLS versions and cipher suites for external traffic are determined by your ingress configuration, not by SecurSpaces. Set them to meet your own policy.
Data at rest
SecurSpaces is customer-hosted, so encryption at rest for the database, persistent volumes, and etcd is your
responsibility. SecurSpaces adds application-layer encryption on top of it.
| Data | Protection |
|---|---|
| Developer and application secrets stored in the database | AES-128-GCM, when the external Vault integration is not in use |
Database, persistent volumes, etcd
|
Your infrastructure encryption, such as cloud provider KMS or encrypted Kubernetes persistent volumes |
Keys and certificates
| Purpose | Algorithm |
|---|---|
| Application secret encryption | AES-128-GCM |
| API tokens | AES-GCM |
| Personal SSH identities | Ed25519 |
| SAML signing certificate, when SecurSpaces acts as the identity provider | RSA 2048 |
| Token signing | JSON Web Token signing keys, held as Kubernetes Secrets |
| TLS | X.509 certificates |
SecurSpaces supports automated certificate lifecycle management for external traffic, such as cert-manager, Let’s Encrypt, or an internal PKI. It manages the certificates for internal cluster traffic itself.
Secret storage
| Secret | Where it is held |
|---|---|
| Developer and application secrets | Encrypted in the database, or in an external HashiCorp Vault instance when that integration is enabled |
| Certificates, access keys, encryption keys, database credentials, token signing keys | Kubernetes Secrets, stored in etcd
|
Kubernetes Secrets are stored in etcd, which you must protect with encryption at rest. For stronger
separation, SecurSpaces works with the Secrets Store CSI Driver and External Secrets Operators.
Related information
Share
Share
This Preview product documentation is Citrix Confidential.
You agree to hold this documentation confidential pursuant to the terms of your Citrix Beta/Tech Preview Agreement.
The development, release and timing of any features or functionality described in the Preview documentation remains at our sole discretion and are subject to change without notice or consultation.
The documentation is for informational purposes only and is not a commitment, promise or legal obligation to deliver any material, code or functionality and should not be relied upon in making Citrix product purchase decisions.
If you do not agree, select I DO NOT AGREE to exit.