Protect keys and secrets
Follow these best practices to secure your keys and secrets:
Store all Private CA integration credentials in an approved secrets-management system.
Do not place credentials, database passwords, or master secrets in configuration files under source control.
Rotate credentials according to your agency's policy and immediately upon suspected exposure.
Restrict access to key escrow and recovery functions.
Review every recovery event.