Commit Graph

1456 Commits (2ec0c24e988e53af6310f3a810cbbef9e02c6de0)
 

Author SHA1 Message Date
Mariano Cano 2ec0c24e98 Update docs for RA. 4 years ago
Mariano Cano d46990d4c4 Add support for step ca init with a RA. 4 years ago
Mariano Cano ef92a3a6d7 Move cas options under authority. 4 years ago
Mariano Cano 6838233416
Merge pull request #395 from smallstep/aws-identity-cert
Add option to specify the AWS IID certificates to use.
4 years ago
Mariano Cano 6a7b564ef9 Unify indent type.
This change changes the indentation used by `step ca init` to be
consistent with Config.Save used by `step ca provisioner *`.
4 years ago
Mariano Cano 7d1686dc53 Add option to specify the AWS IID certificates to use.
This changes adds a new option `iidRoots` that allows a user to
define one or more certificates that will be used for AWS IID
signature validation.

Fixes #393
4 years ago
Mariano Cano 647b9b4541
Merge pull request #367 from smallstep/cas
Support for CAS Interface and CloudCAS
4 years ago
Mariano Cano 3e0ab8fba7 Fix typo. 4 years ago
Mariano Cano d64427487d Add comment about the missing error check. 4 years ago
Mariano Cano 8381e9bd17 Fix typos. 4 years ago
Carl Tashian 329f401e58
Update cas.md
Needed to run two commands to set up IAM roles because passing `--role` twice only uses the second value passed.
4 years ago
Carl Tashian 3f55f22b2e
Update cas.md
Added `--location` flag to a couple of the commands
4 years ago
Carl Tashian c963883d60
Merge pull request #377 from smallstep/gh-discussions
Change Gitter links to GH Discussions tab
4 years ago
Mariano Cano 7d779e12db Change service account name. 4 years ago
Mariano Cano 52d857a302 Update CloudCAS instructions. 4 years ago
Mariano Cano 066c7ee10b Fix iam permissions. 4 years ago
Carl Tashian fd07e25e61 Change Gitter links to GH Discussions tab 4 years ago
Mariano Cano 42ce78ed43 Add initial docs for CAS. 4 years ago
Mariano Cano 072adc906e Print root fingerprint for CloudCAS. 4 years ago
Mariano Cano 8e6d7accf8 Do not add the CRL distribution points extension.
This extension is added by CloudCAS.
4 years ago
Mariano Cano 38fa780775 Add interface to get root certificate from CAS.
This change makes easier the configuration of cloudCAS as it does
not require to configure the root or intermediate certificate
in the ca.json. CloudCAS will get the root certificate using
the configured certificateAuthority.
4 years ago
Mariano Cano fa099f2ae2 Change method name. 4 years ago
Mariano Cano d0086fe9ba
Merge pull request #375 from smallstep/admin-templates
Use new admin template for K8ssa and admin-OIDC provisioners.
4 years ago
Mariano Cano 4c8bf87dc1 Use new admin template for K8ssa and admin-OIDC provisioners.
This change replaces the .Insecure.CR template to one that sets
all the SANs, but uses key usages and extended key usages for
regular TLS certificates.
4 years ago
Mariano Cano 309d9ddcc4
Merge pull request #374 from smallstep/missing-token-ids
Create a hash of a token if a token id is empty.
4 years ago
Mariano Cano d79b4e709e Create a hash of a token if a token id is empty. 4 years ago
Mariano Cano 656315bd61
Merge pull request #371 from smallstep/bundle-awskms-init
Add step-awskms-init to the binary releases.
4 years ago
Mariano Cano c2fd6a8421 Add step-awskms-init to the binary releases.
Fixes 332
4 years ago
Mariano Cano 4f3b24af8f
Merge pull request #370 from smallstep/yubi-management-key
Make the YubiKey management key configurable.
4 years ago
Mariano Cano f100b2d0e3 Make the YubiKey management key configurable.
With this change the default management key is not required as the
user is able to set its own.

Fixes #323
4 years ago
Mariano Cano a332c40530 Merge branch 'master' into cas 4 years ago
Mariano Cano 87bbcee239 Update go.sum 4 years ago
Mariano Cano 9573b47efb
Merge pull request #369 from acipia/master
avoid using yubikey attestation cert
4 years ago
max furman 3e874a1e72 Fix RHEL/CentOS install docs 4 years ago
Mariano Cano 884a6f5dd0 Skip test on CI. 4 years ago
Mariano Cano 91aa1e87f1 Do not use go 1.15 methods. 4 years ago
Mariano Cano 60515d92c5 Remove unnecessary properties. 4 years ago
Pierre Laden 692f7692a2 fix #2 indentation 4 years ago
Pierre Laden 290d5ee979 fix gofmt complain 4 years ago
Pierre Laden 179e793f1a - provide PINpolicy always to piv-go to avoid trying to use attestation cert, which we might not have
- bump piv-go version to 1.6.0
4 years ago
Mariano Cano f2dd5c48cc Fix linting errors. 4 years ago
Mariano Cano 8957e5e5a2 Add missing tests 4 years ago
Mariano Cano e146b3fe16 Add Unit tests for softcas. 4 years ago
Mariano Cano 1550a21f68 Fix unit tests. 4 years ago
Mariano Cano e17ce39e3a Add support for Revoke using CAS. 4 years ago
Mariano Cano 144ffe73dd Complete unit tests for Google CAS. 4 years ago
Mariano Cano f7d066fca8 Fix key usages. 4 years ago
Mariano Cano 01e6495f43 Add most of cloudcas unit tests and minor fixes. 4 years ago
Mariano Cano 8eff4e77a8 Comment request structs. 4 years ago
Mariano Cano bd8dd9da41 Do not read issuer and signer twice. 4 years ago