start updating images pki

This commit is contained in:
Tuan Dang
2025-11-06 16:46:09 -08:00
parent b7c7ec36c8
commit fdd367a0e8
16 changed files with 24 additions and 23 deletions

View File

@@ -277,9 +277,9 @@ the certificate back to the intermediate CA.
<Tab title="Infisical UI"> <Tab title="Infisical UI">
Head to the CA Page of the CA you wish you renew and press **Renew CA** on Head to the CA Page of the CA you wish you renew and press **Renew CA** on
the left side. ![pki ca renewal the left side. ![pki ca renewal
page](/images/platform/pki/ca-renewal-page.png) Input a new **Valid Until** page](/images/platform/pki/ca/ca-renewal.png) Input a new **Valid Until**
date to be used for the renewed CA certificate and press **Renew** to renew date to be used for the renewed CA certificate and press **Renew** to renew
the CA. ![pki ca renewal. modal](/images/platform/pki/ca-renewal-modal.png) the CA. ![pki ca renewal. modal](/images/platform/pki/ca/ca-renewal-modal.png)
<Note> <Note>
The new **Valid Until** date must be within the validity period of the The new **Valid Until** date must be within the validity period of the
parent CA. parent CA.

View File

@@ -13,7 +13,9 @@ You typically request certificates against a certificate profile through its ass
To create a certificate profile, head to your Certificate Management Project > Certificates > Certificate Profiles and press **Create Profile**. To create a certificate profile, head to your Certificate Management Project > Certificates > Certificate Profiles and press **Create Profile**.
TODO: image ![pki certificate profile](/images/platform/pki/certificate/cert-profile.png)
![pki certificate profile modal](/images/platform/pki/certificate/cert-profile-modal.png)
Here's some guidance on each field: Here's some guidance on each field:

View File

@@ -13,11 +13,13 @@ Each certificate requested against a profile is validated against the template b
To create a certificate template, head to your Certificate Management Project > Certificates > Certificate Templates and press **Create Template**. To create a certificate template, head to your Certificate Management Project > Certificates > Certificate Templates and press **Create Template**.
TODO: image ![pki certificate template](/images/platform/pki/certificate/cert-template.png)
![pki certificate template modal](/images/platform/pki/certificate/cert-template-modal.png)
Here's some guidance on each field: Here's some guidance on each field:
- Template Name: The name of the template such as `tls-server`. - Template Name: A slug-friendly name for the template such as `tls-server`.
- Description: An optional description for the template. - Description: An optional description for the template.
- Subject Attributes: A list of common names that can be included in the certificate subject. Each row accepts a fixed value or pattern such as `example.com` or `*.example.com` and whether it is allowed or denied. - Subject Attributes: A list of common names that can be included in the certificate subject. Each row accepts a fixed value or pattern such as `example.com` or `*.example.com` and whether it is allowed or denied.
- Subject Alternative Names (SANs): A list of SANs that can appear in the certificate. Each row accepts a SAN type (e.g. DNS, IP, Email, URI), a fixed value or pattern such as `example.com` or `*.example.com`, and an allow or deny flag. - Subject Alternative Names (SANs): A list of SANs that can appear in the certificate. Each row accepts a SAN type (e.g. DNS, IP, Email, URI), a fixed value or pattern such as `example.com` or `*.example.com`, and an allow or deny flag.

View File

@@ -52,15 +52,14 @@ Here, select the certificate profile from step 1 that will be used to issue the
<Tab title="API"> <Tab title="API">
<Steps> <Steps>
<Step title="Creating a certificate template"> <Step title="Create a certificate profile">
A certificate template is a set of policies for certificates issued under that template; each template is bound to a specific CA and can also be bound to a certificate collection for alerting such that any certificate issued under the template is automatically added to the collection.
With certificate templates, you can specify, for example, that issued certificates must have a common name (CN) adhering to a specific format like .*.acme.com or perhaps that the max TTL cannot be more than 1 year. To create a certificate [profile](/documentation/platform/pki/certificates/profiles), make an API request to the [Create Certificate Profile](/docs/api-reference/endpoints/certificate-profiles/create) API endpoint.
To create a certificate template, make an API request to the [Create Certificate Template](/api-reference/endpoints/certificate-templates/create) API endpoint, specifying the issuing CA.
### Sample request ### Sample request
TODO: update this sample request.
```bash Request ```bash Request
curl --location --request POST 'https://app.infisical.com/api/v1/pki/certificate-templates' \ curl --location --request POST 'https://app.infisical.com/api/v1/pki/certificate-templates' \
--header 'Content-Type: application/json' \ --header 'Content-Type: application/json' \
@@ -87,10 +86,13 @@ Here, select the certificate profile from step 1 that will be used to issue the
``` ```
</Step> </Step>
<Step title="Creating a certificate"> <Step title="Issue a certificate">
To create a certificate under the certificate template, make an API request to the [Issue Certificate](/api-reference/endpoints/certificates/issue-cert) API endpoint,
TODO: update this sample request.
To issue a certificate against the certificate profile, make an API request to the [Issue Certificate](/api-reference/endpoints/certificates/issue-cert) API endpoint,
specifying the issuing CA. specifying the issuing CA.
### Sample request ### Sample request
```bash Request ```bash Request
@@ -115,18 +117,13 @@ Here, select the certificate profile from step 1 that will be used to issue the
} }
``` ```
<Note>
Note that Infisical PKI supports issuing certificates without certificate templates as well. If this is desired, then you can set the **Certificate Template** field to **None**
and specify the **Issuing CA** and optional **Certificate Collection** fields; the rest of the fields for the issued certificate remain the same.
That said, we recommend using certificate templates to enforce policies and attach expiration monitoring on issued certificates.
</Note>
<Note> <Note>
Make sure to store the `privateKey` as it is only returned once here at the time of certificate issuance. The `certificate` and `certificateChain` will remain accessible and can be retrieved at any time. Make sure to store the `privateKey` as it is only returned once here at the time of certificate issuance. The `certificate` and `certificateChain` will remain accessible and can be retrieved at any time.
</Note> </Note>
If you have an external private key, you can also create a certificate by making an API request containing a pem-encoded CSR (Certificate Signing Request) to the [Sign Certificate](/api-reference/endpoints/certificates/sign-certificate) API endpoint, specifying the issuing CA. TODO: update this sample request.
If you have an external private key, you can also issue a certificate by making an API request containing a pem-encoded CSR (Certificate Signing Request) to the [Sign Certificate](/api-reference/endpoints/certificates/sign-certificate) API endpoint, specifying the issuing CA.
### Sample request ### Sample request

Binary file not shown.

Before

Width:  |  Height:  |  Size: 439 KiB

After

Width:  |  Height:  |  Size: 372 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 417 KiB

After

Width:  |  Height:  |  Size: 369 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 671 KiB

After

Width:  |  Height:  |  Size: 275 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 775 KiB

After

Width:  |  Height:  |  Size: 697 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 693 KiB

After

Width:  |  Height:  |  Size: 297 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 370 KiB

After

Width:  |  Height:  |  Size: 334 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 488 KiB

After

Width:  |  Height:  |  Size: 310 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 358 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 281 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 518 KiB

After

Width:  |  Height:  |  Size: 326 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 275 KiB

View File

@@ -94,7 +94,7 @@ export const PkiManagerLayout = () => {
</Link> </Link>
{ {
<> <>
{ {/* {
<Link <Link
to="/projects/cert-management/$projectId/subscribers" to="/projects/cert-management/$projectId/subscribers"
params={{ params={{
@@ -105,7 +105,7 @@ export const PkiManagerLayout = () => {
<Tab value={isActive ? "selected" : ""}>Subscribers (Legacy)</Tab> <Tab value={isActive ? "selected" : ""}>Subscribers (Legacy)</Tab>
)} )}
</Link> </Link>
} } */}
{(subscription.pkiLegacyTemplates || hasExistingTemplates) && ( {(subscription.pkiLegacyTemplates || hasExistingTemplates) && (
<Link <Link
to="/projects/cert-management/$projectId/certificate-templates" to="/projects/cert-management/$projectId/certificate-templates"