v1

latestOpenAPI 3.0.02026-07-246171,3332.1 MB
v2

post/update-ssh-cert-issuer

Request body

ProviderTypestring
add-tagstring[]

List of the new tags that will be attached to this item

allowed-usersstring required

Users allowed to fetch the certificate, e.g root,ubuntu

delete_protectionstring

Protection from accidental deletion of this object [true/false]

descriptionstring

Description of the object

extensionsobject

Signed certificates with extensions, e.g permit-port-forwarding=""

external-usernamestring

Externally provided username [true/false]

fixed-user-claim-keynamestring

For externally provided users, denotes the key-name of IdP claim to extract the username from (relevant only for external-username=true)

host-providerstring

Host provider type [explicit/target], Default Host provider is explicit, Relevant only for Secure Remote Access of ssh cert issuer, ldap rotated secret and ldap dynamic secret

item-custom-fieldsobject

Additional custom fields to associate with the item

jsonboolean

Set output format to JSON

metadatastring

Deprecated - use description

namestring required

SSH certificate issuer name

new-namestring

New item name

principalsstring

Signed certificates with principal, e.g example_role1,example_role2

rm-tagstring[]

List of the existent tags that will be removed from this item

secure-access-apistring

Secure Access SSH control API endpoint. E.g. https://my.sra-server:9900

secure-access-bastion-apistring

Deprecated. use secure-access-api

secure-access-bastion-sshstring

Deprecated. use secure-access-ssh

secure-access-enablestring

Enable/Disable secure remote access [true/false]

secure-access-enforce-hosts-restrictionboolean

Enable this flag to enforce connections only to the hosts listed in --secure-access-host

secure-access-gatewaystring
secure-access-hoststring[]

Target servers for connections (In case of Linked Target association, host(s) will inherit Linked Target hosts - Relevant only for Dynamic Secrets/producers)

secure-access-sshstring

Bastion's SSH server. E.g. my.sra-server:22

secure-access-ssh-creds-userstring

SSH username to connect to target server, must be in 'Allowed Users' list

secure-access-use-internal-bastionboolean

Deprecated. Use secure-access-use-internal-ssh-access

secure-access-use-internal-ssh-accessboolean

Use internal SSH Access

signer-key-namestring required

A key to sign the certificate with

tokenstring

Authentication token (see /auth and /configure)

ttlinteger required

The requested Time To Live for the certificate, in seconds

uid-tokenstring

The universal identity token, Required only for universal_identity authentication

Response

updateSSHCertIssuerResponse wraps response body.

namestring