mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 03:26:12 +00:00
continue pki docs restructuring
This commit is contained in:
+23
-23
@@ -728,30 +728,30 @@
|
|||||||
},
|
},
|
||||||
"documentation/platform/pki/subscribers",
|
"documentation/platform/pki/subscribers",
|
||||||
"documentation/platform/pki/certificates",
|
"documentation/platform/pki/certificates",
|
||||||
"documentation/platform/pki/acme-ca",
|
|
||||||
"documentation/platform/pki/azure-adcs",
|
|
||||||
"documentation/platform/pki/est",
|
"documentation/platform/pki/est",
|
||||||
"documentation/platform/pki/alerting",
|
"documentation/platform/pki/alerting"
|
||||||
{
|
]
|
||||||
"group": "Integrations",
|
},
|
||||||
"pages": [
|
{
|
||||||
"documentation/platform/pki/pki-issuer",
|
"group": "Infrastructure Integrations",
|
||||||
"documentation/platform/pki/integration-guides/gloo-mesh"
|
"pages": [
|
||||||
]
|
"documentation/platform/pki/pki-issuer",
|
||||||
},
|
"documentation/platform/pki/integration-guides/gloo-mesh"
|
||||||
{
|
]
|
||||||
"group": "Certificate Syncs",
|
},
|
||||||
"pages": [
|
{
|
||||||
"documentation/platform/pki/certificate-syncs/overview",
|
"group": "Certificate Syncs",
|
||||||
{
|
"pages": [
|
||||||
"group": "Syncs",
|
"documentation/platform/pki/certificate-syncs/overview",
|
||||||
"pages": [
|
"documentation/platform/pki/certificate-syncs/aws-certificate-manager",
|
||||||
"documentation/platform/pki/certificate-syncs/aws-certificate-manager",
|
"documentation/platform/pki/certificate-syncs/azure-key-vault"
|
||||||
"documentation/platform/pki/certificate-syncs/azure-key-vault"
|
]
|
||||||
]
|
},
|
||||||
}
|
{
|
||||||
]
|
"group": "CA Integrations",
|
||||||
}
|
"pages": [
|
||||||
|
"documentation/platform/pki/acme-ca",
|
||||||
|
"documentation/platform/pki/azure-adcs"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: "Certificates with ACME CA"
|
title: "ACME CA"
|
||||||
description: "Learn how to automatically provision and manage TLS certificates using ACME Certificate Authorities like Let's Encrypt with Infisical PKI"
|
description: "Learn how to automatically provision and manage TLS certificates using ACME Certificate Authorities like Let's Encrypt with Infisical PKI"
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -257,6 +257,7 @@ In the following steps, we explore how to set up ACME Certificate Authority inte
|
|||||||
- Downloaded directly from the Infisical UI
|
- Downloaded directly from the Infisical UI
|
||||||
- Retrieved via the Infisical API for programmatic access using the [latest certificate bundle endpoint](/api-reference/endpoints/pki/subscribers/get-latest-cert-bundle)
|
- Retrieved via the Infisical API for programmatic access using the [latest certificate bundle endpoint](/api-reference/endpoints/pki/subscribers/get-latest-cert-bundle)
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
## Example: Let's Encrypt Integration
|
## Example: Let's Encrypt Integration
|
||||||
@@ -264,19 +265,23 @@ In the following steps, we explore how to set up ACME Certificate Authority inte
|
|||||||
Let's Encrypt is a free, automated, and open Certificate Authority that provides domain-validated SSL/TLS certificates. Here's how the integration works with Infisical:
|
Let's Encrypt is a free, automated, and open Certificate Authority that provides domain-validated SSL/TLS certificates. Here's how the integration works with Infisical:
|
||||||
|
|
||||||
### Production Environment
|
### Production Environment
|
||||||
|
|
||||||
- **Directory URL**: `https://acme-v02.api.letsencrypt.org/directory`
|
- **Directory URL**: `https://acme-v02.api.letsencrypt.org/directory`
|
||||||
- **Rate Limits**: 50 certificates per registered domain per week
|
- **Rate Limits**: 50 certificates per registered domain per week
|
||||||
- **Certificate Validity**: 90 days with automatic renewal
|
- **Certificate Validity**: 90 days with automatic renewal
|
||||||
- **Trusted By**: All major browsers and operating systems
|
- **Trusted By**: All major browsers and operating systems
|
||||||
|
|
||||||
### Staging Environment (for testing)
|
### Staging Environment (for testing)
|
||||||
|
|
||||||
- **Directory URL**: `https://acme-staging-v02.api.letsencrypt.org/directory`
|
- **Directory URL**: `https://acme-staging-v02.api.letsencrypt.org/directory`
|
||||||
- **Rate Limits**: Much higher limits for testing
|
- **Rate Limits**: Much higher limits for testing
|
||||||
- **Certificate Validity**: 90 days (not trusted by browsers)
|
- **Certificate Validity**: 90 days (not trusted by browsers)
|
||||||
- **Use Case**: Testing your ACME integration without hitting production rate limits
|
- **Use Case**: Testing your ACME integration without hitting production rate limits
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Always test your ACME integration using Let's Encrypt's staging environment first. This allows you to verify your DNS configuration and certificate issuance process without consuming your production rate limits.
|
Always test your ACME integration using Let's Encrypt's staging environment
|
||||||
|
first. This allows you to verify your DNS configuration and certificate
|
||||||
|
issuance process without consuming your production rate limits.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
## Example: DigiCert Integration
|
## Example: DigiCert Integration
|
||||||
@@ -289,7 +294,9 @@ DigiCert is a leading commercial Certificate Authority providing a wide range of
|
|||||||
- **Trusted By**: All major browsers and operating systems.
|
- **Trusted By**: All major browsers and operating systems.
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
When integrating with DigiCert ACME, ensure you have obtained the necessary External Account Binding (EAB) Key Identifier (KID) and HMAC Key from your DigiCert account.
|
When integrating with DigiCert ACME, ensure you have obtained the necessary
|
||||||
|
External Account Binding (EAB) Key Identifier (KID) and HMAC Key from your
|
||||||
|
DigiCert account.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
## FAQ
|
## FAQ
|
||||||
@@ -303,11 +310,13 @@ DigiCert is a leading commercial Certificate Authority providing a wide range of
|
|||||||
- Can be fully automated without manual intervention
|
- Can be fully automated without manual intervention
|
||||||
|
|
||||||
Support for additional DNS providers is planned for future releases.
|
Support for additional DNS providers is planned for future releases.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can I use wildcard certificates with ACME CAs?">
|
<Accordion title="Can I use wildcard certificates with ACME CAs?">
|
||||||
Yes! ACME CAs like Let's Encrypt support wildcard certificates (e.g., `*.example.com`) when using DNS-01 validation. Simply specify the wildcard domain in your subscriber configuration.
|
Yes! ACME CAs like Let's Encrypt support wildcard certificates (e.g., `*.example.com`) when using DNS-01 validation. Simply specify the wildcard domain in your subscriber configuration.
|
||||||
|
|
||||||
Note that wildcard certificates still require DNS-01 validation - HTTP-01 validation cannot be used for wildcard certificates.
|
Note that wildcard certificates still require DNS-01 validation - HTTP-01 validation cannot be used for wildcard certificates.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="How long are ACME certificates valid?">
|
<Accordion title="How long are ACME certificates valid?">
|
||||||
Most ACME providers issue certificates with 90-day validity periods. This shorter validity period is designed to:
|
Most ACME providers issue certificates with 90-day validity periods. This shorter validity period is designed to:
|
||||||
@@ -317,6 +326,7 @@ DigiCert is a leading commercial Certificate Authority providing a wide range of
|
|||||||
- Ensure systems stay up-to-date with certificate management practices
|
- Ensure systems stay up-to-date with certificate management practices
|
||||||
|
|
||||||
When configured, Infisical automatically handles certificate renewal for subscribers.
|
When configured, Infisical automatically handles certificate renewal for subscribers.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="Can I use multiple ACME providers?">
|
<Accordion title="Can I use multiple ACME providers?">
|
||||||
Yes! You can register multiple ACME CAs in the same project:
|
Yes! You can register multiple ACME CAs in the same project:
|
||||||
@@ -326,5 +336,6 @@ DigiCert is a leading commercial Certificate Authority providing a wide range of
|
|||||||
- Backup providers for redundancy
|
- Backup providers for redundancy
|
||||||
|
|
||||||
Each subscriber can be configured to use a specific ACME CA based on your requirements.
|
Each subscriber can be configured to use a specific ACME CA based on your requirements.
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: "Certificates with Azure ADCS"
|
title: "Azure ADCS"
|
||||||
description: "Learn how to issue and manage certificates using Microsoft Active Directory Certificate Services (ADCS) with Infisical."
|
description: "Learn how to issue and manage certificates using Microsoft Active Directory Certificate Services (ADCS) with Infisical."
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -24,67 +24,56 @@ This section walks you through the complete end-to-end process of setting up Azu
|
|||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Navigate to External Certificate Authorities">
|
<Step title="Navigate to External Certificate Authorities">
|
||||||
In your Infisical project, go to your **Certificate Project** → **Certificate Authority** to access the external CAs page.
|
In your Infisical project, go to your **Certificate Project** →
|
||||||
|
**Certificate Authority** to access the external CAs page. 
|
Page](/images/platform/pki/azure-adcs/azure-adcs-external-ca-page.png)
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Create New Azure ADCS Certificate Service CA">
|
|
||||||
Click **Create CA** and configure:
|
|
||||||
- **Type**: Choose **Azure AD Certificate Service**
|
|
||||||
- **Name**: Friendly name for this CA (e.g., "Production ADCS CA")
|
|
||||||
- **App Connection**: Choose your ADCS connection from the dropdown
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Certificate Authority Created">
|
|
||||||
Once created, your Azure ADCS Certificate Authority will appear in the list and be ready for use.
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Navigate to Subscribers">
|
|
||||||
Go to **Subscribers** to access the subscribers page.
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Create New Subscriber">
|
|
||||||
Click **Add Subscriber** and configure:
|
|
||||||
- **Name**: Unique subscriber name (e.g., "web-server-certs")
|
|
||||||
- **Certificate Authority**: Select your ADCS CA
|
|
||||||
- **Common Name**: Certificate CN (e.g., "api.example.com")
|
|
||||||
- **Certificate Template**: Select from dynamically loaded ADCS templates
|
|
||||||
- **Subject Alternative Names**: DNS names, IP addresses, or email addresses
|
|
||||||
- **TTL**: Certificate validity period (e.g., "1y" for 1 year)
|
|
||||||
- **Additional Subject Fields**: Organization, OU, locality, state, country, email (if required by template)
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Subscriber Created">
|
|
||||||
Your subscriber is now created and ready to issue certificates.
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Issue New Certificate">
|
|
||||||
Click into your subscriber and click **Order Certificate** to generate a new certificate using your ADCS template.
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
|
|
||||||
<Step title="Certificate Created">
|
|
||||||
Your certificate has been successfully issued by the ADCS server and is ready for use.
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
</Step>
|
||||||
|
<Step title="Create New Azure ADCS Certificate Service CA">
|
||||||
|
Click **Create CA** and configure: - **Type**: Choose **Azure AD Certificate
|
||||||
|
Service** - **Name**: Friendly name for this CA (e.g., "Production ADCS CA") -
|
||||||
|
**App Connection**: Choose your ADCS connection from the dropdown 
|
||||||
|
</Step>
|
||||||
|
<Step title="Certificate Authority Created">
|
||||||
|
Once created, your Azure ADCS Certificate Authority will appear in the list
|
||||||
|
and be ready for use. 
|
||||||
|
</Step>
|
||||||
|
<Step title="Navigate to Subscribers">
|
||||||
|
Go to **Subscribers** to access the subscribers page. 
|
||||||
|
</Step>
|
||||||
|
<Step title="Create New Subscriber">
|
||||||
|
Click **Add Subscriber** and configure: - **Name**: Unique subscriber name
|
||||||
|
(e.g., "web-server-certs") - **Certificate Authority**: Select your ADCS CA -
|
||||||
|
**Common Name**: Certificate CN (e.g., "api.example.com") - **Certificate
|
||||||
|
Template**: Select from dynamically loaded ADCS templates - **Subject
|
||||||
|
Alternative Names**: DNS names, IP addresses, or email addresses - **TTL**:
|
||||||
|
Certificate validity period (e.g., "1y" for 1 year) - **Additional Subject
|
||||||
|
Fields**: Organization, OU, locality, state, country, email (if required by
|
||||||
|
template) 
|
||||||
|
</Step>
|
||||||
|
<Step title="Subscriber Created">
|
||||||
|
Your subscriber is now created and ready to issue certificates. 
|
||||||
|
</Step>
|
||||||
|
<Step title="Issue New Certificate">
|
||||||
|
Click into your subscriber and click **Order Certificate** to generate a new
|
||||||
|
certificate using your ADCS template. 
|
||||||
|
</Step>
|
||||||
|
<Step title="Certificate Created">
|
||||||
|
Your certificate has been successfully issued by the ADCS server and is ready
|
||||||
|
for use. 
|
||||||
|
</Step>
|
||||||
|
|
||||||
<Step title="View Certificate Details">
|
<Step title="View Certificate Details">
|
||||||
Navigate to **Certificates** to view detailed information about all issued certificates, including expiration dates, serial numbers, and certificate chains.
|
Navigate to **Certificates** to view detailed information about all issued
|
||||||
|
certificates, including expiration dates, serial numbers, and certificate
|
||||||

|
chains. 
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
@@ -95,6 +84,7 @@ Infisical automatically retrieves available certificate templates from your ADCS
|
|||||||
### Common Template Types
|
### Common Template Types
|
||||||
|
|
||||||
ADCS templates you might see include:
|
ADCS templates you might see include:
|
||||||
|
|
||||||
- **Web Server**: For SSL/TLS certificates with server authentication
|
- **Web Server**: For SSL/TLS certificates with server authentication
|
||||||
- **Computer**: For machine authentication certificates
|
- **Computer**: For machine authentication certificates
|
||||||
- **User**: For client authentication certificates
|
- **User**: For client authentication certificates
|
||||||
@@ -106,13 +96,16 @@ ADCS templates you might see include:
|
|||||||
### Template Requirements
|
### Template Requirements
|
||||||
|
|
||||||
Ensure your ADCS templates are configured with:
|
Ensure your ADCS templates are configured with:
|
||||||
|
|
||||||
- **Enroll permissions** for your connection account
|
- **Enroll permissions** for your connection account
|
||||||
- **Auto-enroll permissions** if using automated workflows
|
- **Auto-enroll permissions** if using automated workflows
|
||||||
- **Subject name requirements** matching your certificate requests
|
- **Subject name requirements** matching your certificate requests
|
||||||
- **Key usage extensions** appropriate for your use case
|
- **Key usage extensions** appropriate for your use case
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
**Dynamic Template Discovery**: Infisical queries your ADCS server in real-time to populate available templates. Only templates you have permission to use will be displayed during certificate issuance.
|
**Dynamic Template Discovery**: Infisical queries your ADCS server in
|
||||||
|
real-time to populate available templates. Only templates you have permission
|
||||||
|
to use will be displayed during certificate issuance.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
## Certificate Issuance Limitations
|
## Certificate Issuance Limitations
|
||||||
@@ -120,10 +113,13 @@ Ensure your ADCS templates are configured with:
|
|||||||
### Immediate Issuance Only
|
### Immediate Issuance Only
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
**Manual Approval Not Supported**: Infisical currently supports only **immediate certificate issuance**. Certificates that require manual approval or are held by ADCS policies cannot be issued through Infisical yet.
|
**Manual Approval Not Supported**: Infisical currently supports only
|
||||||
|
**immediate certificate issuance**. Certificates that require manual approval
|
||||||
|
or are held by ADCS policies cannot be issued through Infisical yet.
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
For successful certificate issuance, ensure your ADCS templates and policies are configured to:
|
For successful certificate issuance, ensure your ADCS templates and policies are configured to:
|
||||||
|
|
||||||
- **Auto-approve** certificate requests without manual intervention
|
- **Auto-approve** certificate requests without manual intervention
|
||||||
- **Not require** administrator approval for the templates you plan to use
|
- **Not require** administrator approval for the templates you plan to use
|
||||||
- **Allow** the connection account to request and receive certificates immediately
|
- **Allow** the connection account to request and receive certificates immediately
|
||||||
@@ -131,19 +127,22 @@ For successful certificate issuance, ensure your ADCS templates and policies are
|
|||||||
### What Happens with Manual Approval
|
### What Happens with Manual Approval
|
||||||
|
|
||||||
If a certificate request requires manual approval:
|
If a certificate request requires manual approval:
|
||||||
|
|
||||||
1. The request will be submitted to ADCS successfully
|
1. The request will be submitted to ADCS successfully
|
||||||
2. Infisical will attempt to retrieve the certificate with exponential backoff (up to 5 retries over ~1 minute)
|
2. Infisical will attempt to retrieve the certificate with exponential backoff (up to 5 retries over ~1 minute)
|
||||||
3. If the certificate is not approved within this timeframe, the request will **fail**
|
3. If the certificate is not approved within this timeframe, the request will **fail**
|
||||||
4. **No background polling**: Currently, Infisical does not check for certificates that might be approved hours or days later
|
4. **No background polling**: Currently, Infisical does not check for certificates that might be approved hours or days later
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
**Future Enhancement**: Background polling for delayed certificate approvals is planned for future releases.
|
**Future Enhancement**: Background polling for delayed certificate approvals
|
||||||
|
is planned for future releases.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
### Certificate Revocation
|
### Certificate Revocation
|
||||||
|
|
||||||
<Warning>
|
<Warning>
|
||||||
Certificate revocation is **not supported** by the Azure ADCS connector due to security and complexity considerations.
|
Certificate revocation is **not supported** by the Azure ADCS connector due to
|
||||||
|
security and complexity considerations.
|
||||||
</Warning>
|
</Warning>
|
||||||
|
|
||||||
## Advanced Configuration
|
## Advanced Configuration
|
||||||
@@ -166,28 +165,33 @@ This allows Infisical to control certificate expiration dates directly.
|
|||||||
### Common Issues
|
### Common Issues
|
||||||
|
|
||||||
**Certificate Request Denied**
|
**Certificate Request Denied**
|
||||||
|
|
||||||
- Verify ADCS template permissions for your connection account
|
- Verify ADCS template permissions for your connection account
|
||||||
- Check template subject name requirements
|
- Check template subject name requirements
|
||||||
- Ensure template allows the requested key algorithm and size
|
- Ensure template allows the requested key algorithm and size
|
||||||
|
|
||||||
**Revocation Service Unavailable**
|
**Revocation Service Unavailable**
|
||||||
|
|
||||||
- Verify IIS is running and the revocation endpoint is accessible
|
- Verify IIS is running and the revocation endpoint is accessible
|
||||||
- Check IIS application pool permissions
|
- Check IIS application pool permissions
|
||||||
- Test endpoint connectivity from Infisical
|
- Test endpoint connectivity from Infisical
|
||||||
|
|
||||||
**Template Not Found**
|
**Template Not Found**
|
||||||
|
|
||||||
- Verify template exists on ADCS server and is published
|
- Verify template exists on ADCS server and is published
|
||||||
- Check that your connection account has enrollment permissions for the template
|
- Check that your connection account has enrollment permissions for the template
|
||||||
- Ensure the template is properly configured and available in the ADCS web enrollment interface
|
- Ensure the template is properly configured and available in the ADCS web enrollment interface
|
||||||
- Templates are dynamically loaded - refresh the PKI Subscriber form if templates don't appear
|
- Templates are dynamically loaded - refresh the PKI Subscriber form if templates don't appear
|
||||||
|
|
||||||
**Certificate Request Pending/Timeout**
|
**Certificate Request Pending/Timeout**
|
||||||
|
|
||||||
- Check if your ADCS template requires manual approval - Infisical only supports immediate issuance
|
- Check if your ADCS template requires manual approval - Infisical only supports immediate issuance
|
||||||
- Verify the certificate template is configured for auto-approval
|
- Verify the certificate template is configured for auto-approval
|
||||||
- Ensure your connection account has sufficient permissions to request certificates without approval
|
- Ensure your connection account has sufficient permissions to request certificates without approval
|
||||||
- Review ADCS server policies that might be holding the certificate request
|
- Review ADCS server policies that might be holding the certificate request
|
||||||
|
|
||||||
**Network Connectivity Issues**
|
**Network Connectivity Issues**
|
||||||
|
|
||||||
- Verify your ADCS server's firewall allows connections from Infisical
|
- Verify your ADCS server's firewall allows connections from Infisical
|
||||||
- For Infisical Cloud: Ensure Infisical's IP addresses are whitelisted (see [Networking Configuration](/documentation/setup/networking))
|
- For Infisical Cloud: Ensure Infisical's IP addresses are whitelisted (see [Networking Configuration](/documentation/setup/networking))
|
||||||
- For self-hosted: Whitelist your Infisical server's IP address on the ADCS server
|
- For self-hosted: Whitelist your Infisical server's IP address on the ADCS server
|
||||||
@@ -195,11 +199,13 @@ This allows Infisical to control certificate expiration dates directly.
|
|||||||
- Check for any network security appliances blocking the connection
|
- Check for any network security appliances blocking the connection
|
||||||
|
|
||||||
**Authentication Failures**
|
**Authentication Failures**
|
||||||
|
|
||||||
- Verify ADCS connection credentials
|
- Verify ADCS connection credentials
|
||||||
- Check domain account permissions
|
- Check domain account permissions
|
||||||
- Ensure network connectivity to ADCS server
|
- Ensure network connectivity to ADCS server
|
||||||
|
|
||||||
**SSL/TLS Certificate Errors**
|
**SSL/TLS Certificate Errors**
|
||||||
|
|
||||||
- For ADCS servers with self-signed or private certificates: disable "Reject Unauthorized" in the SSL tab of your Azure ADCS app connection, or provide the certificate in PEM format
|
- For ADCS servers with self-signed or private certificates: disable "Reject Unauthorized" in the SSL tab of your Azure ADCS app connection, or provide the certificate in PEM format
|
||||||
- Common SSL errors: `UNABLE_TO_VERIFY_LEAF_SIGNATURE`, `SELF_SIGNED_CERT_IN_CHAIN`, `CERT_HAS_EXPIRED`
|
- Common SSL errors: `UNABLE_TO_VERIFY_LEAF_SIGNATURE`, `SELF_SIGNED_CERT_IN_CHAIN`, `CERT_HAS_EXPIRED`
|
||||||
- The SSL configuration applies to all HTTPS communications between Infisical and your ADCS server
|
- The SSL configuration applies to all HTTPS communications between Infisical and your ADCS server
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: "Gloo Mesh Integration"
|
title: "Gloo Mesh"
|
||||||
description: "Learn how to automatically provision and manage Istio intermediate CA certificates for Gloo Mesh using Infisical PKI"
|
description: "Learn how to automatically provision and manage Istio intermediate CA certificates for Gloo Mesh using Infisical PKI"
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -18,8 +18,8 @@ With this approach, you get the following benefits:
|
|||||||
- Use cert-manager to automatically issue and renew Istio intermediate CA certificates from the same root, ensuring cross-cluster workload communication.
|
- Use cert-manager to automatically issue and renew Istio intermediate CA certificates from the same root, ensuring cross-cluster workload communication.
|
||||||
- Increased auditability of private key infrastructure.
|
- Increased auditability of private key infrastructure.
|
||||||
|
|
||||||
|
|
||||||
## General Setup
|
## General Setup
|
||||||
|
|
||||||
The certificate provisioning workflow begins with setting up your PKI hierarchy in Infisical, where you create root and subordinate certificate authorities.
|
The certificate provisioning workflow begins with setting up your PKI hierarchy in Infisical, where you create root and subordinate certificate authorities.
|
||||||
When you deploy a `Certificate` CRD in your workload cluster, `cert-manager` uses the Infisical PKI Issuer controller to authenticate with Infisical using machine identity credentials and request an intermediate CA certificate.
|
When you deploy a `Certificate` CRD in your workload cluster, `cert-manager` uses the Infisical PKI Issuer controller to authenticate with Infisical using machine identity credentials and request an intermediate CA certificate.
|
||||||
Infisical verifies the request against your certificate templates and returns the signed certificate.
|
Infisical verifies the request against your certificate templates and returns the signed certificate.
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
title: "Cert Manager Issuer"
|
title: "Kubernetes Issuer"
|
||||||
description: "Learn how to automatically provision and manage TLS certificates in Kubernetes using Infisical PKI"
|
description: "Learn how to automatically provision and manage TLS certificates in Kubernetes using Infisical PKI"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user