Skip to content

Commit 2992ea7

Browse files
Merge branch 'dnspluginsupport' of https://github.com/Keyfactor/hydrantid-caplugin into dnspluginsupport
2 parents 9b6cf4c + 263995d commit 2992ea7

1 file changed

Lines changed: 10 additions & 0 deletions

File tree

‎README.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -210,6 +210,7 @@ The plugin supports the following standard CRL revocation reasons:
210210
| **HydrantIdOrgCityProvPostalCodeCountry** | Organization city/province/postal code/country, paired with HydrantIdOrgName. | No | `Anytown, OH 44131, US` |
211211
| **HydrantIdEmailAddress** | Organization contact email address, paired with HydrantIdOrgName. | No | `jane@acme.com` |
212212
| **HydrantIdPhoneNumber** | Organization contact phone number, paired with HydrantIdOrgName. | No | `+1-555-555-0100` |
213+
| **CertificateAuthorityId** | Scopes this logical CA to a single certificate authority within the HydrantId tenant, identified by the `certificateAuthorityId` GUID that `GET /api/v2/policies` reports on each policy. **Strongly recommended when the tenant issues from more than one CA.** HydrantId's policy and certificate endpoints are account-scoped, not CA-scoped, so leaving this blank means every logical CA defined against the tenant offers every policy as a Product ID, synchronizes every certificate, and can revoke any of them — define one logical CA per HydrantId CA and set this on each. When set: only this CA's policies are offered and usable for enrollment, only their certificates synchronize, and reading or revoking a certificate issued under another CA's policy is refused. If the value matches no policy, operations fail with a message saying so rather than silently falling back to unscoped. Leave blank for a single-CA tenant. | No | `1800d95f-9291-435a-b376-fed916be95d0` |
213214
| **DnsPropagationDelaySeconds** | Seconds to wait after a DNS provider plugin writes the validation TXT record before asking HydrantId to check it. Only used on the automated path; ignored when validation is done by hand. Set to `0` to start polling immediately. Defaults to `30` when blank. | No | `30` |
214215
| **DomainValidationTimeoutSeconds** | Maximum seconds to hold the enrollment open while polling HydrantId for domain validation after a DNS provider plugin has staged the record. On timeout the enrollment falls back to external validation rather than failing. Defaults to `300` when blank. | No | `300` |
215216
| **DomainValidationPollIntervalSeconds** | Seconds between HydrantId domain validation status checks while waiting for a staged record. Defaults to `10` when blank. | No | `10` |
@@ -517,6 +518,15 @@ Confirm via the policy list that `details.validator` is unset for the policy und
517518
| G3 | Sync reflects revocation | After F1's revoke, run sync | That cert's status updates to Revoked in Command if not already updated at revoke time |
518519
| G4 | Sync with a large result set | If the HydrantId account has more than 100 certs | Paging completes without missing/duplicating certs |
519520
| G5 | Sync cancellation | Start a sync and cancel it mid-run (if Command exposes this) | Job stops cleanly, no hung state |
521+
| G6 | Per-CA scoping with `CertificateAuthorityId` | On a tenant that issues from more than one CA, read a policy's `certificateAuthorityId` from `GET /api/v2/policies`, set it on this CA, run a full sync | Only certificates issued under that CA's policies appear under this logical CA; the Gateway log's `SyncComplete` step reports a non-zero `filtered=` count for the ones excluded |
522+
| G7 | Two logical CAs, one tenant | Define two logical CAs against the same tenant, each with a different `CertificateAuthorityId`, run a full sync on both | Neither CA's inventory contains the other's certificates (no cross-contamination) |
523+
| G8 | `CertificateAuthorityId` blank | Leave `CertificateAuthorityId` blank, run a full sync | Every certificate in the tenant syncs — the behaviour before the setting existed; no policy lookup is performed |
524+
| G9 | Wrong `CertificateAuthorityId` | Set `CertificateAuthorityId` to a GUID that matches no policy, run a sync | Sync fails with a message naming the configured value and how many policies report a `certificateAuthorityId` — it does **not** silently sync everything |
525+
| G10 | Template picker is scoped | With `CertificateAuthorityId` set, open the Certificate Template / Product ID picker for this CA | Only this CA's policies are listed, so a template cannot be mapped to a policy that issues from a different CA |
526+
| G11 | Enrollment against a foreign policy | Map a template to a policy belonging to another CA (or change `CertificateAuthorityId` after mapping), then enroll | Enrollment fails before submission with a message naming the policy's CA and this CA's configured CA — nothing is issued |
527+
| G12 | Read a foreign certificate | With `CertificateAuthorityId` set, ask this CA for a certificate issued under another CA's policy | Refused with a message naming the certificate's policy, this CA's configured CA, and how to resolve it — not returned as if it belonged to this CA |
528+
| G13 | Revoke a foreign certificate | With `CertificateAuthorityId` set, attempt to revoke a certificate issued under another CA's policy | Refused before any revocation is submitted; the certificate remains valid at HydrantId |
529+
| G14 | Revoke own certificate still works | Revoke a certificate issued under this CA's own policy | Revocation succeeds as before (one extra ownership read is performed first) |
520530

521531
### H. Negative / edge cases
522532

0 commit comments

Comments
 (0)