Ugo Gabriele De Santis
Design and Implementation of a Secure Device-to-Enterprise VPN Communication Channel with Automated Certificate Rotation.
Rel. Alessandro Savino, Stefano Di Carlo, Vincenzo Cacciatore. Politecnico di Torino, Corso di laurea magistrale in Cybersecurity, 2026
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (1MB) | Preview |
Abstract
This thesis focuses on the design and implementation of a secure and reliable communication channel between edge devices located at customer premises and the enterprise network. The proposed solution is based on a VPN architecture that ensures encrypted, authenticated, and tamper-resistant communication between distributed devices and internal services. A key feature of the design is the automated rotation of digital certificates through HashiCorp Vault, which enables dynamic credential management, reduces the risk of credential compromise, and removes the need for manual certificate maintenance. OpenLDAP serves as the centralized identity store and single source of truth shared between OpenVPN-AS and Keycloak, ensuring consistent credential management across the entire infrastructure.
The architecture implements a two-layer security model: network access is controlled at the VPN level via LDAP credential verification and mutual certificate authentication, while resource access is further restricted by Keycloak-based authorization after the VPN session is established
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Corso di laurea
Classe di laurea
Aziende collaboratrici
URI
![]() |
Modifica (riservato agli operatori) |
