start updating images pki
@@ -277,9 +277,9 @@ the certificate back to the intermediate CA.
|
||||
<Tab title="Infisical UI">
|
||||
Head to the CA Page of the CA you wish you renew and press **Renew CA** on
|
||||
the left side.  Input a new **Valid Until**
|
||||
page](/images/platform/pki/ca/ca-renewal.png) Input a new **Valid Until**
|
||||
date to be used for the renewed CA certificate and press **Renew** to renew
|
||||
the CA. 
|
||||
the CA. 
|
||||
<Note>
|
||||
The new **Valid Until** date must be within the validity period of the
|
||||
parent CA.
|
||||
|
||||
@@ -13,7 +13,9 @@ You typically request certificates against a certificate profile through its ass
|
||||
|
||||
To create a certificate profile, head to your Certificate Management Project > Certificates > Certificate Profiles and press **Create Profile**.
|
||||
|
||||
TODO: image
|
||||

|
||||
|
||||

|
||||
|
||||
Here's some guidance on each field:
|
||||
|
||||
|
||||
@@ -13,11 +13,13 @@ Each certificate requested against a profile is validated against the template b
|
||||
|
||||
To create a certificate template, head to your Certificate Management Project > Certificates > Certificate Templates and press **Create Template**.
|
||||
|
||||
TODO: image
|
||||

|
||||
|
||||

|
||||
|
||||
Here's some guidance on each field:
|
||||
|
||||
- Template Name: The name of the template such as `tls-server`.
|
||||
- Template Name: A slug-friendly name for the template such as `tls-server`.
|
||||
- Description: An optional description for the template.
|
||||
- Subject Attributes: A list of common names that can be included in the certificate subject. Each row accepts a fixed value or pattern such as `example.com` or `*.example.com` and whether it is allowed or denied.
|
||||
- Subject Alternative Names (SANs): A list of SANs that can appear in the certificate. Each row accepts a SAN type (e.g. DNS, IP, Email, URI), a fixed value or pattern such as `example.com` or `*.example.com`, and an allow or deny flag.
|
||||
|
||||
@@ -52,15 +52,14 @@ Here, select the certificate profile from step 1 that will be used to issue the
|
||||
<Tab title="API">
|
||||
|
||||
<Steps>
|
||||
<Step title="Creating a certificate template">
|
||||
A certificate template is a set of policies for certificates issued under that template; each template is bound to a specific CA and can also be bound to a certificate collection for alerting such that any certificate issued under the template is automatically added to the collection.
|
||||
<Step title="Create a certificate profile">
|
||||
|
||||
With certificate templates, you can specify, for example, that issued certificates must have a common name (CN) adhering to a specific format like .*.acme.com or perhaps that the max TTL cannot be more than 1 year.
|
||||
|
||||
To create a certificate template, make an API request to the [Create Certificate Template](/api-reference/endpoints/certificate-templates/create) API endpoint, specifying the issuing CA.
|
||||
To create a certificate [profile](/documentation/platform/pki/certificates/profiles), make an API request to the [Create Certificate Profile](/docs/api-reference/endpoints/certificate-profiles/create) API endpoint.
|
||||
|
||||
### Sample request
|
||||
|
||||
TODO: update this sample request.
|
||||
|
||||
```bash Request
|
||||
curl --location --request POST 'https://app.infisical.com/api/v1/pki/certificate-templates' \
|
||||
--header 'Content-Type: application/json' \
|
||||
@@ -87,10 +86,13 @@ Here, select the certificate profile from step 1 that will be used to issue the
|
||||
```
|
||||
|
||||
</Step>
|
||||
<Step title="Creating a certificate">
|
||||
To create a certificate under the certificate template, make an API request to the [Issue Certificate](/api-reference/endpoints/certificates/issue-cert) API endpoint,
|
||||
<Step title="Issue a certificate">
|
||||
|
||||
TODO: update this sample request.
|
||||
|
||||
To issue a certificate against the certificate profile, make an API request to the [Issue Certificate](/api-reference/endpoints/certificates/issue-cert) API endpoint,
|
||||
specifying the issuing CA.
|
||||
|
||||
|
||||
### Sample request
|
||||
|
||||
```bash Request
|
||||
@@ -115,18 +117,13 @@ Here, select the certificate profile from step 1 that will be used to issue the
|
||||
}
|
||||
```
|
||||
|
||||
<Note>
|
||||
Note that Infisical PKI supports issuing certificates without certificate templates as well. If this is desired, then you can set the **Certificate Template** field to **None**
|
||||
and specify the **Issuing CA** and optional **Certificate Collection** fields; the rest of the fields for the issued certificate remain the same.
|
||||
|
||||
That said, we recommend using certificate templates to enforce policies and attach expiration monitoring on issued certificates.
|
||||
</Note>
|
||||
|
||||
<Note>
|
||||
Make sure to store the `privateKey` as it is only returned once here at the time of certificate issuance. The `certificate` and `certificateChain` will remain accessible and can be retrieved at any time.
|
||||
</Note>
|
||||
|
||||
If you have an external private key, you can also create a certificate by making an API request containing a pem-encoded CSR (Certificate Signing Request) to the [Sign Certificate](/api-reference/endpoints/certificates/sign-certificate) API endpoint, specifying the issuing CA.
|
||||
TODO: update this sample request.
|
||||
|
||||
If you have an external private key, you can also issue a certificate by making an API request containing a pem-encoded CSR (Certificate Signing Request) to the [Sign Certificate](/api-reference/endpoints/certificates/sign-certificate) API endpoint, specifying the issuing CA.
|
||||
|
||||
### Sample request
|
||||
|
||||
|
||||
|
Before Width: | Height: | Size: 439 KiB After Width: | Height: | Size: 372 KiB |
|
Before Width: | Height: | Size: 417 KiB After Width: | Height: | Size: 369 KiB |
|
Before Width: | Height: | Size: 671 KiB After Width: | Height: | Size: 275 KiB |
|
Before Width: | Height: | Size: 775 KiB After Width: | Height: | Size: 697 KiB |
|
Before Width: | Height: | Size: 693 KiB After Width: | Height: | Size: 297 KiB |
|
Before Width: | Height: | Size: 370 KiB After Width: | Height: | Size: 334 KiB |
|
Before Width: | Height: | Size: 488 KiB After Width: | Height: | Size: 310 KiB |
BIN
docs/images/platform/pki/certificate/cert-profile-modal.png
Normal file
|
After Width: | Height: | Size: 358 KiB |
BIN
docs/images/platform/pki/certificate/cert-profile.png
Normal file
|
After Width: | Height: | Size: 281 KiB |
|
Before Width: | Height: | Size: 518 KiB After Width: | Height: | Size: 326 KiB |
BIN
docs/images/platform/pki/certificate/cert-template.png
Normal file
|
After Width: | Height: | Size: 275 KiB |
@@ -94,7 +94,7 @@ export const PkiManagerLayout = () => {
|
||||
</Link>
|
||||
{
|
||||
<>
|
||||
{
|
||||
{/* {
|
||||
<Link
|
||||
to="/projects/cert-management/$projectId/subscribers"
|
||||
params={{
|
||||
@@ -105,7 +105,7 @@ export const PkiManagerLayout = () => {
|
||||
<Tab value={isActive ? "selected" : ""}>Subscribers (Legacy)</Tab>
|
||||
)}
|
||||
</Link>
|
||||
}
|
||||
} */}
|
||||
{(subscription.pkiLegacyTemplates || hasExistingTemplates) && (
|
||||
<Link
|
||||
to="/projects/cert-management/$projectId/certificate-templates"
|
||||
|
||||