smallstep / certificates

🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH.
https://smallstep.com/certificates
Apache License 2.0
6.81k stars 445 forks source link

Allow Tokens for Renewing Certificates #2042

Open hunoz opened 1 month ago

hunoz commented 1 month ago

Name of feature: Provide Functionality for Tokens to be Used for Renewing Certificates

Pain or issue this feature alleviates: Currently, a provisioner doesn't allow for tokens to be used in the provisioner.RenewWithToken function as the audience is set to use /1.0/sign, which makes the token invalid for renewing certificates.

Why is this important to the project (if not answered above): Renewal of certificates via tokens issued with a provisioner is required for planned application usage.

Is there documentation on how to use this feature? If so, where?

None that I am aware of.

In what environments or workflows is this feature supported?

Any environments where this usage is planned or expected.

In what environments or workflows is this feature explicitly NOT supported (if any)?

None

Supporting links/other PRs/issues: N/A

💔Thank you!

CLAassistant commented 1 month ago

CLA assistant check
All committers have signed the CLA.

CLAassistant commented 1 month ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.