You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+10Lines changed: 10 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -210,6 +210,7 @@ The plugin supports the following standard CRL revocation reasons:
210
210
|**HydrantIdOrgCityProvPostalCodeCountry**| Organization city/province/postal code/country, paired with HydrantIdOrgName. | No |`Anytown, OH 44131, US`|
211
211
|**HydrantIdEmailAddress**| Organization contact email address, paired with HydrantIdOrgName. | No |`jane@acme.com`|
212
212
|**HydrantIdPhoneNumber**| Organization contact phone number, paired with HydrantIdOrgName. | No |`+1-555-555-0100`|
213
+
|**CertificateAuthorityId**| Scopes this logical CA to a single certificate authority within the HydrantId tenant, identified by the `certificateAuthorityId` GUID that `GET /api/v2/policies` reports on each policy. **Strongly recommended when the tenant issues from more than one CA.** HydrantId's policy and certificate endpoints are account-scoped, not CA-scoped, so leaving this blank means every logical CA defined against the tenant offers every policy as a Product ID, synchronizes every certificate, and can revoke any of them — define one logical CA per HydrantId CA and set this on each. When set: only this CA's policies are offered and usable for enrollment, only their certificates synchronize, and reading or revoking a certificate issued under another CA's policy is refused. If the value matches no policy, operations fail with a message saying so rather than silently falling back to unscoped. Leave blank for a single-CA tenant. | No | `1800d95f-9291-435a-b376-fed916be95d0` |
213
214
| **DnsPropagationDelaySeconds** | Seconds to wait after a DNS provider plugin writes the validation TXT record before asking HydrantId to check it. Only used on the automated path; ignored when validation is done by hand. Set to `0` to start polling immediately. Defaults to `30` when blank. | No | `30` |
214
215
| **DomainValidationTimeoutSeconds** | Maximum seconds to hold the enrollment open while polling HydrantId for domain validation after a DNS provider plugin has staged the record. On timeout the enrollment falls back to external validation rather than failing. Defaults to `300` when blank. | No | `300` |
215
216
| **DomainValidationPollIntervalSeconds** | Seconds between HydrantId domain validation status checks while waiting for a staged record. Defaults to `10` when blank. | No | `10` |
@@ -517,6 +518,15 @@ Confirm via the policy list that `details.validator` is unset for the policy und
517
518
| G3 | Sync reflects revocation | After F1's revoke, run sync | That cert's status updates to Revoked in Command if not already updated at revoke time |
518
519
| G4 | Sync with a large result set | If the HydrantId account has more than 100 certs | Paging completes without missing/duplicating certs |
519
520
| G5 | Sync cancellation | Start a sync and cancel it mid-run (if Command exposes this) | Job stops cleanly, no hung state |
521
+
| G6 | Per-CA scoping with `CertificateAuthorityId` | On a tenant that issues from more than one CA, read a policy's `certificateAuthorityId` from `GET /api/v2/policies`, set it on this CA, run a full sync | Only certificates issued under that CA's policies appear under this logical CA; the Gateway log's `SyncComplete` step reports a non-zero `filtered=` count for the ones excluded |
522
+
| G7 | Two logical CAs, one tenant | Define two logical CAs against the same tenant, each with a different `CertificateAuthorityId`, run a full sync on both | Neither CA's inventory contains the other's certificates (no cross-contamination) |
523
+
| G8 |`CertificateAuthorityId` blank | Leave `CertificateAuthorityId` blank, run a full sync | Every certificate in the tenant syncs — the behaviour before the setting existed; no policy lookup is performed |
524
+
| G9 | Wrong `CertificateAuthorityId`| Set `CertificateAuthorityId` to a GUID that matches no policy, run a sync | Sync fails with a message naming the configured value and how many policies report a `certificateAuthorityId` — it does **not** silently sync everything |
525
+
| G10 | Template picker is scoped | With `CertificateAuthorityId` set, open the Certificate Template / Product ID picker for this CA | Only this CA's policies are listed, so a template cannot be mapped to a policy that issues from a different CA |
526
+
| G11 | Enrollment against a foreign policy | Map a template to a policy belonging to another CA (or change `CertificateAuthorityId` after mapping), then enroll | Enrollment fails before submission with a message naming the policy's CA and this CA's configured CA — nothing is issued |
527
+
| G12 | Read a foreign certificate | With `CertificateAuthorityId` set, ask this CA for a certificate issued under another CA's policy | Refused with a message naming the certificate's policy, this CA's configured CA, and how to resolve it — not returned as if it belonged to this CA |
528
+
| G13 | Revoke a foreign certificate | With `CertificateAuthorityId` set, attempt to revoke a certificate issued under another CA's policy | Refused before any revocation is submitted; the certificate remains valid at HydrantId |
529
+
| G14 | Revoke own certificate still works | Revoke a certificate issued under this CA's own policy | Revocation succeeds as before (one extra ownership read is performed first) |
0 commit comments