Mariano Cano
4fd9a9b92b
Disable database if WithNoDB() option is passed
...
This commit removes the database from the configuration if the ca was
initialized with the "--no-db" flag.
Fixes #1292
2 years ago
Herman Slatman
a9359522e6
Add provisioner and super admin subject output to `ca init`
...
When initializing a CA with `--remote-management`, it wasn't made
clear that the default JWK provisioner is used when authenticating
for administration purposes and that a default `step` user is
created to login with. This commit adds some additional information
to the CLI output on completion of `ca init`.
2 years ago
Herman Slatman
fd38dd34f9
Fix PR comments
2 years ago
Herman Slatman
49718f1bbb
Fix some comments
2 years ago
Herman Slatman
d981b9e0dc
Add `--admin-subject` flag to `ca init`
...
The first super admin subject can now be provided through the
`--admin-subject` flag when initializing a CA.
It's not yet possible to configure the subject of the first
super admin when provisioners are migrated from `ca.json` to the
database. This effectively limits usage of the flag to scenarios
in which the provisioners are written to the database immediately,
so when `--remote-management` is enabled. It currently also doesn't
work with Helm deployments, because there's no mechanism yet to
pass this type of option to the Helm chart.
This commit partially addresses https://github.com/smallstep/cli/issues/697
2 years ago
Herman Slatman
c423e2f664
Improve Helm test data to be more realistic
2 years ago
Herman Slatman
317efa4568
Add some TODOs for improvingin PKI initialization maintainability
2 years ago
max furman
ab0d2503ae
Standardize linting file and fix or ignore lots of linting errors
2 years ago
Mariano Cano
369b8f81c3
Use go.step.sm/crypto/kms
...
Fixes #975
2 years ago
Carl Tashian
9848caf49f
Create the db directory on step ca init
3 years ago
max furman
7fac8c96c3
Merge branch 'master' into max/context
3 years ago
max furman
d37313bef4
Use 0600 for profile defaults file.
3 years ago
max furman
fcc15174ea
Rename templates and create profileConfig dir ahead of time.
3 years ago
max furman
43cba993bb
PR fixes
...
- Line -> PrependLine
- dont' overwrite profileDefaults
- update ssh/config.tpl to always include includes file
3 years ago
max furman
3e9830e363
Use profileDefaults in PKI
...
- write profile defaults at the same time as authority defaults
3 years ago
max furman
d777fc23c2
Add ca.WithInsecure and use methods for file names
3 years ago
max furman
ed4b56732e
updates after rebase to keep up with master
3 years ago
max furman
7eeebca529
Enable step path contexts in identity and pki paths
3 years ago
max furman
10db335f13
mv pkg config -> step
3 years ago
Mariano Cano
a2b03083c8
Fix gocritic warnings.
3 years ago
Mariano Cano
e15b5faf7d
Merge branch 'master' into keyvault
3 years ago
Mariano Cano
5d0bd7d155
Fix grammar in comments.
3 years ago
Mariano Cano
781d5fb6e8
Fix creation of ssh certificates on step ca init.
3 years ago
max furman
933b40a02a
Introduce gocritic linter and address warnings
3 years ago
Mariano Cano
ece67fefff
Add support for kms in pki package.
...
Adding support to kms in the pki packages opens the door to use
kms implementations in `step ca init`
3 years ago
Mariano Cano
4fde7b5250
Use badgerv2 the default in helm too.
...
Use also port 443 for the ca-url, as we usually access through the
service, this can be overridden by --with-ca-url flag in the cli.
3 years ago
Mariano Cano
8cb62b6d67
Fix ssh in helm chart values.
3 years ago
Mariano Cano
516b74f43a
Add comment about unused code.
3 years ago
Mariano Cano
ff25f4974f
Fix comment.
3 years ago
Mariano Cano
b1f59586ab
Update message to align with UI.
3 years ago
Mariano Cano
66f6c73655
Update badger driver to use v2 by default.
3 years ago
Mariano Cano
072ba4227c
Add deployment type to config.
...
This field is ignored except for the start of the ca. If the type
is linked and the token is not passed, it will fail with an error.
3 years ago
Mariano Cano
56bb3eb6e1
Add next steps for linked ca.
3 years ago
Mariano Cano
47a30f1524
Add JWK provisioner to generic config.
...
Fix linter errors.
3 years ago
Mariano Cano
640f523150
Remove unused function.
3 years ago
Mariano Cano
81004ce1f9
Remove deprecated functions.
3 years ago
Mariano Cano
79cf059447
Remove deprecated methods and write all pki files at once.
3 years ago
Mariano Cano
ad4dbd6764
Write all files on save.
3 years ago
Mariano Cano
50f7a0d0c0
Work in progress implementation of PKI with helm support
3 years ago
Mariano Cano
721459210e
Make pki initialization more flexible.
3 years ago
max furman
7b5d6968a5
first commit
3 years ago
Mariano Cano
9270d432ea
Remove unused code.
4 years ago
Mariano Cano
1d48f00723
Add method to create a CertificateAuthorityResponse.
4 years ago
Mariano Cano
2b4b902975
Add initial support for `step ca init` with cloud cas.
...
Fixes smallstep/cli#363
4 years ago
Mariano Cano
40d0596b71
Use smallstep/cli-utils instead of smallstep/cli
4 years ago
Mariano Cano
d46990d4c4
Add support for step ca init with a RA.
4 years ago
Mariano Cano
6a7b564ef9
Unify indent type.
...
This change changes the indentation used by `step ca init` to be
consistent with Config.Save used by `step ca provisioner *`.
4 years ago
Carl Tashian
fd07e25e61
Change Gitter links to GH Discussions tab
4 years ago
Mariano Cano
c94a1c51be
Merge branch 'master' into ssh-cert-templates
4 years ago
Mariano Cano
ba918100d0
Use go.step.sm/crypto/jose
...
Replace use of github.com/smallstep/cli/crypto with the new package
go.step.sm/crypto/jose.
4 years ago