You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
List of the new tags that will be attached to this item
[optional]
allowed_users
String
Users allowed to fetch the certificate, e.g root,ubuntu
delete_protection
String
Protection from accidental deletion of this object [true/false]
[optional]
description
String
Description of the object
[optional]
extensions
Hash<String, String>
Signed certificates with extensions, e.g permit-port-forwarding=\"\"
[optional]
host_provider
String
Host provider type [explicit/target], Default Host provider is explicit, Relevant only for Secure Remote Access of ssh cert issuer, ldap rotated secret and ldap dynamic secret
[optional]
json
Boolean
Set output format to JSON
[optional][default to false]
metadata
String
Deprecated - use description
[optional]
name
String
SSH certificate issuer name
new_name
String
New item name
[optional]
principals
String
Signed certificates with principal, e.g example_role1,example_role2
[optional]
rm_tag
Array<String>
List of the existent tags that will be removed from this item
Enable this flag to enforce connections only to the hosts listed in --secure-access-host
[optional]
secure_access_host
Array<String>
Target servers for connections (In case of Linked Target association, host(s) will inherit Linked Target hosts - Relevant only for Dynamic Secrets/producers)
[optional]
secure_access_ssh_creds_user
String
SSH username to connect to target server, must be in 'Allowed Users' list
[optional]
secure_access_use_internal_bastion
Boolean
Use internal SSH Bastion
[optional]
signer_key_name
String
A key to sign the certificate with
token
String
Authentication token (see `/auth` and `/configure`)
[optional]
ttl
Integer
The requested Time To Live for the certificate, in seconds
uid_token
String
The universal identity token, Required only for universal_identity authentication