1.0 Introduction
This article describes the minimum access privileges required for Fortanix Key Insight to scan the Oracle Cloud Infrastructure (OCI) cloud compartments and resources.
2.0 Terminology References
For OCI terminology and concepts, refer to All Connections Concepts and OCI Connection Concepts.
3.0 Prerequisites
Ensure that you:
Sign in to the OCI Console.
Have the required Identity and Access Management (IAM) permissions to create users, groups, and policies in the OCI tenancy.
Have the required IAM permissions to add API keys to IAM users
4.0 Create a Group
Create a group and add the IAM user to it.
In the OCI Console, open the navigation menu in the upper-left corner.
Select Identity & Security → Domains.
On the Domains list page, select the domain in which you want to create the group.
Under Identity domain, select Groups.
Click Create group.
In the Name and Description fields, enter the group name and description.
Click Create.
The group is created. You can add the IAM user to this group.
5.0 Create a User
Create an IAM user for Fortanix Key Insight to access the OCI resources to be scanned. You can use an existing IAM user if it has the required permissions.
In the OCI Console, open the navigation menu in the upper-left corner.
Select Identity & Security → Domains.
On the Domains list page, select the domain for which you want to create a user.
Under Identity domain, select Users.
Click Create.
Enter the user’s First name, Last name, and Username / Email.
Select the check box for the group to which you want to add the user.
To create a new group, refer to Section 4.0 Create Group.
Click Create.
The IAM user is created and added to the group. Create a policy that grants the required permissions for OCI scanning.
6.0 Create a Policy
Create an IAM policy that grants the group the required permissions to access the OCI resources to be scanned.
In the OCI Console, open the navigation menu in the upper-left corner.
Select Identity & Security → Policies.
Click Create Policy.
The Create Policy screen appears.
In the Name and Description fields, enter the policy name and description.
From the Compartment drop-down list, select the compartment in which you want to create the policy.
Under Policy Builder, click Show manual editor.
Enter the required policy statement in the manual editor.
For a comprehensive list of OCI permissions required to onboard an OCI connection, refer to the OCI Connection Permissions.
Review the policy.
Click Create.
The IAM policy is created and grants the specified group the required access to the OCI resources.
7.0 Create an API Signing Key (RSA Key-Pair)
Create an RSA key pair with a minimum key size of 2048 bits for Fortanix Key Insight to authenticate to OCI. Add the public key to the IAM user in OCI and securely store the corresponding private key. Obtain the API key fingerprint required to configure the OCI connection in Fortanix Key Insight.
7.1 Generate the RSA Key Pair
Generate the RSA private and public key pair in PEM format for OCI authentication. Securely store the private key for use when configuring the OCI connection.
Run the following command to create a directory to store the keys:
mkdir -p ~/.ociRun the following command to generate a 2048-bit RSA private key:
openssl genrsa -out ~/.oci/keyinsight_api_key.pem 2048NOTE
When configuring the OCI connection, enter only the Base64-encoded content of the RSA private key. Do not include the private key header and footer.
Run the following command to restrict permissions on the private key:
chmod 600 ~/.oci/keyinsight_api_key.pemRun the following command to generate a public key from the private key:
openssl rsa -pubout -in ~/.oci/keyinsight_api_key.pem -out ~/.oci/keyinsight_api_key_public.pem
7.2 Add the Public Key to OCI
Add the generated public key to the IAM user in OCI to enable authentication using the corresponding private key.
Sign in to the OCI Console as the IAM user created in Section 5.0.
Open the Profile menu and select My Profile.
Select Tokens and keys.
Click Add API key.
Add API key panel opens.
Select Choose public key file.
Drag and drop the created RSA public key file into the upload area, or click Drop a file or Select one to select the file from your local system.
Click Add.
OCI adds the public key to the IAM user and displays the API key fingerprint and configuration information.
[DEFAULT]
user=ocid1.user.oc1..xxxxx
fingerprint=xx:xx:xx:...
tenancy=ocid1.tenancy.oc1..xxxxx
region=us-ashburn-1
key_file=~/.oci/keyinsight_api_key.pemCopy the user, fingerprint, tenancy, and region displayed in the OCI configuration snippet. These values are required when onboarding the OCI connection in Key Insight.
For more information, refer to Getting Started with OCI Cloud Connection.