v1
latestOpenAPI 3.0.02026-07-246171,3332.1 MBRequest body
Users allowed to fetch the certificate, e.g root,ubuntu
Protection from accidental deletion of this object [true/false]
Description of the object
Signed certificates with extensions, e.g permit-port-forwarding=""
Externally provided username [true/false]
For externally provided users, denotes the key-name of IdP claim to extract the username from (relevant only for external-username=true)
Host provider type [explicit/target], Default Host provider is explicit, Relevant only for Secure Remote Access of ssh cert issuer, ldap rotated secret and ldap dynamic secret
Additional custom fields to associate with the item
Set output format to JSON
Deprecated - use description
SSH certificate issuer name
Signed certificates with principal, e.g example_role1,example_role2
Secure Access SSH control API endpoint. E.g. https://my.sra-server:9900
Deprecated. use secure-access-api
Deprecated. use secure-access-ssh
Enable/Disable secure remote access [true/false]
Enable this flag to enforce connections only to the hosts listed in --secure-access-host
Target servers for connections (In case of Linked Target association, host(s) will inherit Linked Target hosts - Relevant only for Dynamic Secrets/producers)
Bastion's SSH server. E.g. my.sra-server:22
SSH username to connect to target server, must be in 'Allowed Users' list
Deprecated. Use secure-access-use-internal-ssh-access
Use internal SSH Access
A key to sign the certificate with
List of the tags attached to this key
A list of linked targets to be associated, Relevant only for Secure Remote Access for ssh cert issuer, ldap rotated secret and ldap dynamic secret, To specify multiple targets use argument multiple times
Authentication token (see /auth and /configure)
The requested Time To Live for the certificate, in seconds
The universal identity token, Required only for universal_identity authentication
Response
createSSHCertIssuerResponse wraps response body.