hashicorp / terraform-provider-azuread

Terraform provider for Azure Active Directory
Mozilla Public License 2.0
434 stars 301 forks source link

update resource azuread_service_principal_token_signing_certificate to create standard PEM encoded certificates #1095

Open todd-dsm opened 1 year ago

todd-dsm commented 1 year ago

Please keep in mind that I'm learning Azure/Okta on the go, so I reserve the right to be completely wrong about all of this 😀


I’m attempting to automate the relationship between Azure AD (IdP) and Okta "Identity Providers" configuration. In the Okta docs a certificate must be generated manually in an Azure Enterprise App; that certificate is later downloaded from Azure, then uploaded to the Okta " Identity Providers" config.

I've followed https://github.com/hashicorp/terraform-provider-azuread/issues/823#issuecomment-1398060612 to generate/activate the SSO certificate; seems to work.


The azuread_service_principal_token_signing_certificate does not appear to follow the Terraform principal for cross-provider operations; in this case, the certificate doesn't seem to be output in proper PEM encoding.

New or Affected Resource(s)

Potential Terraform Configuration

# Create a Service Principal for the Enterprise Application
# TF: https://registry.terraform.io/providers/hashicorp/azuread/latest/docs/resources/service_principal
resource "azuread_service_principal" "okta_sp" {
  application_id                = azuread_application.okta.application_id
  owners                        = [data.azurerm_client_config.current.object_id]
  app_role_assignment_required  = false
  preferred_single_sign_on_mode = "saml"

  saml_single_sign_on {}

  feature_tags {
    custom_single_sign_on = true
    enterprise            = true
    gallery               = false
    hide                  = false
  notification_email_addresses = [

# Create a Service Principal Certificate for the Enterprise Application
# TF: https://registry.terraform.io/providers/hashicorp/azuread/latest/docs/resources/service_principal_token_signing_certificate
# REF: https://github.com/hashicorp/terraform-provider-azuread/issues/823#issuecomment-1398060612
resource "azuread_service_principal_token_signing_certificate" "saml_signing_cert" {
  service_principal_id = azuread_service_principal.okta_sp.id
  display_name         = "CN=${var.myCo} SSO Certificate"
  end_date             = time_rotating.saml_certificate.rotation_rfc3339

  provisioner "local-exec" {
    command = <<-SHELL
      az ad sp update --id ${self.service_principal_id} \
        --set preferredTokenSigningKeyThumbprint=${self.thumbprint}

# Rotate Certs on a prescribed timeline: 3 years # default
resource "time_rotating" "saml_certificate" {
  rotation_years = 3

resource "okta_idp_saml_key" "idp_signing_key" {
  x5c = [
    -----END CERTIFICATE-----



manicminer commented 1 year ago

Hi @todd-dsm, thanks for requesting this. That's a very reasonable ask and I'm sure we can output this in a PEM compliant format.