hashicorp / terraform-provider-vault

Terraform Vault provider
https://www.terraform.io/docs/providers/vault/
Mozilla Public License 2.0
451 stars 535 forks source link

[Enhancement]: Allow setting not_after for vault_pki_secret_backend_root_cert #2240

Open mitsutaka opened 1 month ago

mitsutaka commented 1 month ago

Description

Generating a new certificate of the vault API allows specifying the not_after to set the absolute end date instead of ttl. The documentation for the vault_pki_secret_backend_root_cert resource, this parameter can't currently be set when generating a new certificate in Terraform.

Affected Resource(s) and/or Data Source(s)

Potential Terraform Configuration

resource "vault_pki_secret_backend_root_cert" "ca" {
  backend  = vault_mount.pki.path

  ...

  not_after = "2025-01-01T00:00:00Z"
}

References

https://developer.hashicorp.com/vault/api-docs/secret/pki#not_after

Would you like to implement a fix?

None