-
Notifications
You must be signed in to change notification settings - Fork 491
Open
Labels
enhancementneeds triageWaiting for discussion / prioritization by teamWaiting for discussion / prioritization by team
Milestone
Description
Description
Instead of using a JWK/X5c provisioner to request the signing of the certificate to the CA, we can implement some kind of authenticated API similar to Google CAS that defines the certificate that we want to sign.
The CA should always have the right to enforce a template, but the RA should be able to suggest one, as well as be able to define the provisioner extension.
We should add support RA support for SSH certificates.
kaeptnegli
Metadata
Metadata
Assignees
Labels
enhancementneeds triageWaiting for discussion / prioritization by teamWaiting for discussion / prioritization by team