v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/create-ssh-cert-issuer

Request body

ProviderTypestring
allowed-usersstring required

Users allowed to fetch the certificate, e.g root,ubuntu

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Description of the object

extensionsobject

Signed certificates with extensions, e.g permit-port-forwarding=""

external-usernamestring

Externally provided username [true/false]

fixed-user-claim-keynamestring

For externally provided users, denotes the key-name of IdP claim to extract the username from (relevant only for external-username=true)

host-providerstring

Host provider type [explicit/target], Default Host provider is explicit, Relevant only for Secure Remote Access of ssh cert issuer, ldap rotated secret and ldap dynamic secret

item-custom-fieldsobject

Additional custom fields to associate with the item

jsonboolean

Set output format to JSON

metadatastring

Deprecated - use description

namestring required

SSH certificate issuer name

principalsstring

Signed certificates with principal, e.g example_role1,example_role2

secure-access-apistring

Secure Access SSH control API endpoint. E.g. https://my.sra-server:9900

secure-access-bastion-apistring

Deprecated. use secure-access-api

secure-access-bastion-sshstring

Deprecated. use secure-access-ssh

secure-access-enablestring

Enable/Disable secure remote access [true/false]

secure-access-enforce-hosts-restrictionboolean

Enable this flag to enforce connections only to the hosts listed in --secure-access-host

secure-access-gatewaystring
secure-access-hoststring[]

Target servers for connections (In case of Linked Target association, host(s) will inherit Linked Target hosts - Relevant only for Dynamic Secrets/producers)

secure-access-sshstring

Bastion's SSH server. E.g. my.sra-server:22

secure-access-ssh-creds-userstring

SSH username to connect to target server, must be in 'Allowed Users' list

secure-access-use-internal-bastionboolean

Deprecated. Use secure-access-use-internal-ssh-access

secure-access-use-internal-ssh-accessboolean

Use internal SSH Access

signer-key-namestring required

A key to sign the certificate with

tagstring[]

List of the tags attached to this key

targetstring[]

A list of linked targets to be associated, Relevant only for Secure Remote Access for ssh cert issuer, ldap rotated secret and ldap dynamic secret, To specify multiple targets use argument multiple times

tokenstring

Authentication token (see /auth and /configure)

ttlinteger required

The requested Time To Live for the certificate, in seconds

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

Response

createSSHCertIssuerResponse wraps response body.

namestring