You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If I understand your request correctly this is already possible by using an x5c key and certificate as provisioner credentials that point to the yubikey with a kms url.
Oh, in that case I have the exact same issue. Thing is, when using kms backed keys (tpm in my case), step ca token --ssh|--revoke|--rekey work, but step ca token --renew does not. Neither does step ca renew:
Nevermind. I misunderstood the issue. Created a separate one here #1314
For CA administrative functions, it would be nice to be able to use a KMS-bound key.
This enables a flow where a YubiKey could be used to admin the CA, using an admin cert acquired via ACME DA.
The text was updated successfully, but these errors were encountered: