# Kill the shared password and the static key

Canonical: https://brew.new/browse/templates/email/pt1_k97q8tn377dcdt2vq976qf8azd8e5v8n

Brand: goteleport.com
Category: newsletter

![Preview of Kill the shared password and the static key](https://cdn.brew.new/email-preview-790d25696d7ab0eb-tracking_r57sywv9ntpyzggype4mj4ztrh8dte1j-1789006022466.png)

## Email content

Teleport

New in Identity

Teleport — The AI Infrastructure Identity Company | Issue #5

Replacing static credentials looks different depending on where they live. This issue covers three of the trickiest spots: shared database passwords, SSH keys in trading infrastructure, and remote access behind NAT and CGNAT – all problems Teleport is built for.

How to Eliminate Shared Database Passwords: MySQL, PostgreSQL, and More

By Dan Johns

A shared database username tells you what happened, not who did it. When an incident review or audit comes, the logs show the action but not the person behind it. Short-lived certificates fix that: every connection carries an identity, privileges expire automatically, and write access can require hardware key approval. See what query-level attribution looks like in the audit log when the shared password is gone.

Read the full post →

How to Eliminate Static Credentials from Trading Infrastructure

By Gus Luxton

Tatu Ylonen, who invented SSH, warns that one stolen key can compromise an entire server environment. In trading infrastructure those keys carry root access to execution, market data, and order routing. As firms grow, keys spread across thousands of servers through Ansible, and standard rotation fails to contain the risk because the credentials outlive the engineers who provisioned them. Short-lived certificates and machine identity replace static keys without touching the underlying tooling.

Read the full post →

Remote Access That Works Behind NAT, CGNAT, and Uncontrolled Firewalls

By Steven Martin

Inbound SSH needs a stable public IP and an open port, and remote device networks rarely provide either. NAT and CGNAT make connections unroutable, and a VPN breaks the moment a device switches from Wi-Fi to cellular. The fix is reversing the connection direction, multiplexing SSH, Kubernetes, and database access through one outbound tunnel, and replacing IP addresses with device identity so policy survives the network changing underneath it.

Read the full post →

Have questions or want to keep the conversation going? Join us in our Community Slack →

If you found this useful, pass it along to someone else who would, too.

Thanks for reading,

The Teleport Editorial Team

P.S. We'll be at these events over the next few weeks — swing by if you’ll be there too.

Identiverse — Jun 15–19 · Las Vegas, NV | Booth #745

AWS Summit — Jun 17 · New York, NY

PlatformCon London — Jun 23 · London, England

PlatformCon New York — Jun 25 · New York City, NY

BlackHat USA – Aug 1–6 · Las Vegas, NV | Booth #5114

Find us near you →

Teleport, 2100 Franklin St, Suite 400, Oakland, CA 94612

If you no longer wish to receive these emails anymore, click on the following link:

UNSUBSCRIBE

TERMS OF SERVICE | PRIVACY POLICY | SECURITY POLICY

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97q8tn377dcdt2vq976qf8azd8e5v8n)

[Browse email designs](https://brew.new/browse/templates)
