Add create, update, and delete for Certificate Manager configuration

The module was read-only for PKI configuration, which is why standing up an
environment meant raw REST rather than cmdlets. Adds 15: New-, Set-, and Remove-
for certificate authorities, policies, profiles, applications, and PKI
subscribers.

New-InfisicalCertificateAuthority -Type Intermediate returns an authority that
can actually issue. Infisical creates a subordinate with status
pending-certificate and never invokes generateIntermediateCaCertificate from the
create path, so the cmdlet performs the remaining sequence: read the certificate
signing request, sign it with -ParentCaId, import the signed certificate and
chain back.

Policy and profile bodies are deeply nested, so the constraint objects and
per-enrollment-type config blocks are taken as dictionaries rather than as
dozens of parameters, matching how -Subject and -Metadata already work. Two
conversion details matter and are now pinned by tests:

  - PowerShell callers capitalise hashtable keys, and @{ Required = ... } was
    reaching the API as "Required", which its schema does not recognise. The
    constraint vocabulary is emitted lower-cased while every other key keeps its
    camelCase, since those are API field names supplied verbatim and lowercasing
    ttlDays or isCA would silently drop them.
  - An empty collection is omitted rather than sent. "allowed": [] reads to
    Infisical as "allow nothing", never what @{ Allowed = @() } was meant to
    express, and an entry carrying only "type" is rejected outright.

-EnrollmentConfig routes to the block matching -EnrollmentType so EST, ACME, and
SCEP settings arrive through one parameter. -AutoRenew is sent only when bound,
because a switch is false when absent and sending it unconditionally would
disable renewal on an update that never mentioned it.

-ProjectId is optional on all 15 and resolves as it does elsewhere. Every one
supports -WhatIf; Remove- cmdlets default to high confirm impact.

Also fixes Update-Changelog, which inserted the version heading above the notes
so the section the release workflow extracts held only the build line while the
notes stayed under Unreleased - every release published an empty changelog.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-31 17:41:13 -04:00
parent 62131e7501
commit 139d1f3a05
18 changed files with 3007 additions and 7 deletions
+18 -3
View File
@@ -1,6 +1,6 @@
@{
RootModule = 'PSInfisicalAPI.psm1'
ModuleVersion = '2026.07.31.2019'
ModuleVersion = '2026.07.31.2140'
GUID = 'b8a2f3d4-7c51-4d2f-9e6a-1f0c8b3d4e51'
Author = 'Grace Solutions'
CompanyName = 'Grace Solutions'
@@ -62,7 +62,22 @@
'Write-InfisicalScepMdmProfileToWmi',
'Start-InfisicalProcess',
'Get-InfisicalEnvironmentVariable',
'Get-InfisicalSANList'
'Get-InfisicalSANList',
'New-InfisicalCertificateAuthority',
'Set-InfisicalCertificateAuthority',
'Remove-InfisicalCertificateAuthority',
'New-InfisicalCertificatePolicy',
'Set-InfisicalCertificatePolicy',
'Remove-InfisicalCertificatePolicy',
'New-InfisicalCertificateProfile',
'Set-InfisicalCertificateProfile',
'Remove-InfisicalCertificateProfile',
'New-InfisicalCertificateApplication',
'Set-InfisicalCertificateApplication',
'Remove-InfisicalCertificateApplication',
'New-InfisicalPkiSubscriber',
'Set-InfisicalPkiSubscriber',
'Remove-InfisicalPkiSubscriber'
)
AliasesToExport = @()
VariablesToExport = @()
@@ -74,7 +89,7 @@
LicenseUri = 'https://www.gnu.org/licenses/agpl-3.0.html'
ProjectUri = 'https://prod.git.gracesolution.info/gsadmin/PSInfisicalAPI'
ReleaseNotes = 'See CHANGELOG.md in the project repository for release history.'
CommitHash = 'e7674af1617c'
CommitHash = '62131e750109'
}
}
}
Binary file not shown.
@@ -2104,4 +2104,439 @@ $Sans = Get-InfisicalSANList @GetInfisicalSANListParameters</dev:code>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificateAuthority</command:name>
<maml:description><maml:para>Creates an internal Infisical certificate authority, signing a subordinate with its parent.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificateAuthority</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a root or intermediate internal certificate authority in a Certificate Manager project. A root is self-signed on creation. Infisical creates an intermediate pending a certificate and exposes no single call that completes it, so this cmdlet performs the remaining sequence itself: it reads the certificate signing request, signs it with the authority named by -ParentCaId, and imports the signed certificate and chain back, returning an authority that is ready to issue. -NotAfter defaults to ten years for a root and five for an intermediate; -MaxPathLength defaults to 1 for a root and 0 otherwise. -ProjectId is optional and resolves to the organization&apos;s Certificate Manager project.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Certificate authorities created through the API always have direct issuance disabled, because Infisical&apos;s creation service sets it explicitly and exposes no way to change it afterwards. Issue through a certificate profile, which does not consult that flag. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>$Root = New-InfisicalCertificateAuthority -Name &apos;root-ca&apos; -Type Root -CommonName &apos;Contoso Root Certificate Authority&apos; -Organization &apos;Contoso&apos; -Country &apos;US&apos;</dev:code>
<dev:remarks><maml:para>Creates a self-signed root valid for ten years.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificateAuthority -Name &apos;issuing-ca&apos; -Type Intermediate -ParentCaId $Root.Id -CommonName &apos;Contoso Issuing Certificate Authority&apos; -KeyAlgorithm &apos;EC_secp384r1&apos;</dev:code>
<dev:remarks><maml:para>Creates a subordinate, signs it with the root, and imports the signed certificate so it can issue immediately.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificateAuthority</command:name>
<maml:description><maml:para>Renames an internal Infisical certificate authority or changes its status.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificateAuthority</command:noun>
</command:details>
<maml:description>
<maml:para>Updates the name or status of an internal certificate authority. Infisical&apos;s update schema accepts only these two fields; subject, key algorithm, and validity are fixed when the authority is created. Supply -PassThru to emit the updated record.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Disabling an authority stops it issuing without deleting it or the certificates it has already signed. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificateAuthority -CaId $Ca.Id -Status disabled</dev:code>
<dev:remarks><maml:para>Stops the authority issuing new certificates.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificateAuthority -CaId $Ca.Id -Name &apos;retired-issuing-ca&apos; -PassThru</dev:code>
<dev:remarks><maml:para>Renames the authority and emits the updated record.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificateAuthority</command:name>
<maml:description><maml:para>Deletes an internal Infisical certificate authority.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificateAuthority</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes an internal certificate authority from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. Certificates already issued by the authority stop chaining to a known issuer once it is gone, and any subordinate beneath it is orphaned. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificateAuthority -CaId $Ca.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the authority without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificateAuthority -Kind Internal | Where-Object {($_.Status -eq &apos;disabled&apos;)} | Remove-InfisicalCertificateAuthority</dev:code>
<dev:remarks><maml:para>Removes every disabled authority, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificatePolicy</command:name>
<maml:description><maml:para>Creates an Infisical certificate policy that constrains what a profile may issue.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificatePolicy</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a certificate policy: the constraints a certificate profile issues within. Subject attributes, subject alternative names, key usages, and extended key usages are each expressed as allowed, required, and denied sets, supplied as dictionaries so the nested shape stays readable. -MaxValidity caps certificate lifetime, -KeyAlgorithm and -SignatureAlgorithm restrict the cryptography. A constraint that is not supplied leaves that dimension unconstrained, which is what fleet enrollment needs so each machine can present its own name.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Constraint values use Infisical&apos;s snake_case names: digital_signature, key_encipherment, server_auth, client_auth, code_signing, common_name, dns_name, ip_address. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalCertificatePolicy -Name &apos;server-auth&apos; -MaxValidity &apos;90d&apos; -KeyAlgorithm &apos;RSA_2048&apos;,&apos;EC_secp384r1&apos; -KeyUsage @{ Required = @(&apos;digital_signature&apos;,&apos;key_encipherment&apos;) } -ExtendedKeyUsage @{ Required = @(&apos;server_auth&apos;,&apos;client_auth&apos;) }</dev:code>
<dev:remarks><maml:para>Creates a policy for server and client authentication, leaving subject and SANs unconstrained.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificatePolicy -Name &apos;code-signing&apos; -MaxValidity &apos;365d&apos; -ExtendedKeyUsage @{ Required = @(&apos;code_signing&apos;); Denied = @(&apos;server_auth&apos;,&apos;client_auth&apos;) } -SubjectAlternativeName @(@{ Type = &apos;dns_name&apos;; Allowed = @(&apos;*.contoso.com&apos;) })</dev:code>
<dev:remarks><maml:para>Creates a code signing policy that forbids TLS usage and restricts DNS names to one suffix.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificatePolicy</command:name>
<maml:description><maml:para>Updates an Infisical certificate policy.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificatePolicy</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a certificate policy. Only the constraints supplied on the command line are sent; anything omitted keeps its stored value. Supply -PassThru to emit the updated policy.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Changing a policy affects every profile bound to it, and therefore every future certificate those profiles issue. Certificates already issued are unaffected. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificatePolicy -PolicyId $Policy.Id -MaxValidity &apos;30d&apos;</dev:code>
<dev:remarks><maml:para>Shortens the maximum lifetime, leaving every other constraint as it was.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificatePolicy -PolicyId $Policy.Id -ExtendedKeyUsage @{ Required = @(&apos;server_auth&apos;) } -PassThru</dev:code>
<dev:remarks><maml:para>Narrows the extended key usage and emits the updated policy.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificatePolicy</command:name>
<maml:description><maml:para>Deletes an Infisical certificate policy.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificatePolicy</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a certificate policy from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. A profile bound to the policy cannot issue once it is gone, so remove or repoint dependent profiles first. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificatePolicy -PolicyId $Policy.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the policy without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificatePolicy | Where-Object {($_.Name -like &apos;test-*&apos;)} | Remove-InfisicalCertificatePolicy</dev:code>
<dev:remarks><maml:para>Removes every policy whose name begins with test-, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificateProfile</command:name>
<maml:description><maml:para>Creates an Infisical certificate profile that binds an issuing authority to a policy.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificateProfile</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a certificate profile: the object Request-InfisicalCertificate -CertificateProfileId issues against. A profile binds an issuing certificate authority to a certificate policy and exposes it for one enrollment type. -Slug accepts lowercase letters, numbers, and hyphens. -EnrollmentConfig carries the settings for the chosen -EnrollmentType, so EST, ACME, and SCEP settings all arrive through one parameter; for the default api type, -AutoRenew and -RenewBeforeDays are folded into it.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Profile issuance is the only path that does not consult the issuing authority&apos;s direct-issuance flag, so a profile issues successfully against an authority whose EnableDirectIssuance is False. Unlike a PKI subscriber, a profile accepts a per-request common name, which is what makes it suitable for fleet enrollment. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalCertificateProfile -Slug &apos;server-auth&apos; -CertificatePolicyId $Policy.Id -CaId $Ca.Id</dev:code>
<dev:remarks><maml:para>Creates an API enrollment profile bound to a policy and issuing authority.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificateProfile -Slug &apos;workload&apos; -CertificatePolicyId $Policy.Id -CaId $Ca.Id -AutoRenew -RenewBeforeDays 14 -Defaults @{ ttlDays = 90 }</dev:code>
<dev:remarks><maml:para>Creates a profile that renews issued certificates fourteen days before expiry and defaults to a ninety day lifetime.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificateProfile</command:name>
<maml:description><maml:para>Updates an Infisical certificate profile.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificateProfile</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a certificate profile. Only the values supplied on the command line are sent; anything omitted keeps its stored value, including the enrollment type unless -EnrollmentType is passed explicitly. Supply -PassThru to emit the updated profile.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Repointing a profile at a different policy or issuing authority changes what future requests produce. Because certificate reuse is scoped by profile, Request-InfisicalCertificate keeps reusing certificates the profile issued previously until they fall inside their renewal window. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificateProfile -ProfileId $Profile.Id -CertificatePolicyId $NewPolicy.Id</dev:code>
<dev:remarks><maml:para>Repoints the profile at a different policy.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificateProfile -ProfileId $Profile.Id -AutoRenew -RenewBeforeDays 7 -PassThru</dev:code>
<dev:remarks><maml:para>Enables automatic renewal seven days before expiry and emits the updated profile.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificateProfile</command:name>
<maml:description><maml:para>Deletes an Infisical certificate profile.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificateProfile</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a certificate profile from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. Any script requesting certificates through the profile fails once it is gone, and the profile is detached from every application that referenced it. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificateProfile -ProfileId $Profile.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the profile without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificateProfile -ApplicationId $Application.Id | Remove-InfisicalCertificateProfile</dev:code>
<dev:remarks><maml:para>Removes every profile attached to an application, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificateApplication</command:name>
<maml:description><maml:para>Creates an Infisical certificate application to group profiles and certificates.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificateApplication</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a certificate application: the grouping the Infisical console presents profiles, members, and certificates under, and the scope Get-InfisicalCertificateProfile -ApplicationId and Get-InfisicalCertificate -ApplicationId filter by. Certificate profiles can be attached at creation with -ProfileId.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Applications are served only from the organization&apos;s active Certificate Manager project. Creating one in any other cert-manager project fails, which is why -ProjectId resolves to the active project when it is not supplied. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalCertificateApplication -Name &apos;platform&apos; -Description &apos;Endpoint and workload certificates&apos;</dev:code>
<dev:remarks><maml:para>Creates an empty application.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificateApplication -Name &apos;platform&apos; -ProfileId $ServerProfile.Id, $CodeSigningProfile.Id</dev:code>
<dev:remarks><maml:para>Creates an application with two profiles already attached.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificateApplication</command:name>
<maml:description><maml:para>Renames an Infisical certificate application or changes which profiles it holds.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificateApplication</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a certificate application. -Name and -Description change the record; -AddProfileId and -RemoveProfileId change which certificate profiles the application groups. The record and its profile attachments are separate endpoints, so supplying only profile parameters skips the record update entirely. Supply -PassThru to emit the updated application.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Detaching a profile does not delete it; the profile continues to exist and issue, it is simply no longer grouped under the application. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificateApplication -ApplicationId $Application.Id -AddProfileId $Profile.Id</dev:code>
<dev:remarks><maml:para>Attaches a profile to the application.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificateApplication -ApplicationId $Application.Id -Name &apos;endpoint-management&apos; -RemoveProfileId $Old.Id -PassThru</dev:code>
<dev:remarks><maml:para>Renames the application, detaches a profile, and emits the updated record.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificateApplication</command:name>
<maml:description><maml:para>Deletes an Infisical certificate application.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificateApplication</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a certificate application from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. The profiles the application grouped are not deleted, but scripts that locate a profile by application can no longer find it. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificateApplication -ApplicationId $Application.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the application without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificateApplication | Where-Object {($_.CertificateCount -eq 0)} | Remove-InfisicalCertificateApplication</dev:code>
<dev:remarks><maml:para>Removes every application holding no certificates, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalPkiSubscriber</command:name>
<maml:description><maml:para>Creates an Infisical PKI subscriber, a named enrollment identity with a fixed common name.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalPkiSubscriber</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a PKI subscriber: a named enrollment identity that pins one common name, an allowlist of subject alternative names, a lifetime, and the permitted key usages, so a request carries only a certificate signing request. -CommonName is the identity the subscriber issues for, and -SubjectAlternativeName is an allowlist rather than a default.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>A subscriber is a single identity, not a template. Infisical rejects any request whose certificate signing request names a different common name, and rejects any subject alternative name outside the allowlist, so enrolling many machines through subscribers means one subscriber per machine. Use a certificate profile for fleet enrollment. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalPkiSubscriber -Name &apos;web01&apos; -CommonName &apos;WEB01.contoso.com&apos; -CaId $Ca.Id -Ttl &apos;90d&apos;</dev:code>
<dev:remarks><maml:para>Creates a subscriber for one host.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalPkiSubscriber -Name &apos;web01&apos; -CommonName &apos;WEB01.contoso.com&apos; -CaId $Ca.Id -Ttl &apos;90d&apos; -SubjectAlternativeName &apos;WEB01&apos;,&apos;WEB01.contoso.com&apos; -ExtendedKeyUsage &apos;serverAuth&apos;,&apos;clientAuth&apos;</dev:code>
<dev:remarks><maml:para>Creates a subscriber that also permits two subject alternative names and restricts extended key usage.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalPkiSubscriber</command:name>
<maml:description><maml:para>Updates an Infisical PKI subscriber.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalPkiSubscriber</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a PKI subscriber, addressed by its current -Name. Only the values supplied on the command line are sent; anything omitted keeps its stored value. -NewName renames the subscriber. Supply -PassThru to emit the updated record.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Changing -CommonName changes the identity the subscriber issues for, so any script signing against it must present a matching certificate signing request afterwards. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalPkiSubscriber -Name &apos;web01&apos; -Ttl &apos;30d&apos;</dev:code>
<dev:remarks><maml:para>Shortens the lifetime of certificates issued for the subscriber.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalPkiSubscriber -Name &apos;web01&apos; -SubjectAlternativeName &apos;WEB01&apos;,&apos;WEB01.contoso.com&apos;,&apos;www.contoso.com&apos; -PassThru</dev:code>
<dev:remarks><maml:para>Extends the permitted subject alternative names and emits the updated subscriber.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalPkiSubscriber</command:name>
<maml:description><maml:para>Deletes an Infisical PKI subscriber.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalPkiSubscriber</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a PKI subscriber from a Certificate Manager project, addressed by name. -PassThru emits the removed name for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. Any script signing through the subscriber fails once it is gone. Certificates already issued are unaffected. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalPkiSubscriber -Name &apos;web01&apos; -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the subscriber without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalPkiSubscriber | Where-Object {($_.Status -ne &apos;active&apos;)} | Remove-InfisicalPkiSubscriber</dev:code>
<dev:remarks><maml:para>Removes every inactive subscriber, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
</helpItems>
@@ -2104,4 +2104,439 @@ $Sans = Get-InfisicalSANList @GetInfisicalSANListParameters</dev:code>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificateAuthority</command:name>
<maml:description><maml:para>Creates an internal Infisical certificate authority, signing a subordinate with its parent.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificateAuthority</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a root or intermediate internal certificate authority in a Certificate Manager project. A root is self-signed on creation. Infisical creates an intermediate pending a certificate and exposes no single call that completes it, so this cmdlet performs the remaining sequence itself: it reads the certificate signing request, signs it with the authority named by -ParentCaId, and imports the signed certificate and chain back, returning an authority that is ready to issue. -NotAfter defaults to ten years for a root and five for an intermediate; -MaxPathLength defaults to 1 for a root and 0 otherwise. -ProjectId is optional and resolves to the organization&apos;s Certificate Manager project.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Certificate authorities created through the API always have direct issuance disabled, because Infisical&apos;s creation service sets it explicitly and exposes no way to change it afterwards. Issue through a certificate profile, which does not consult that flag. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>$Root = New-InfisicalCertificateAuthority -Name &apos;root-ca&apos; -Type Root -CommonName &apos;Contoso Root Certificate Authority&apos; -Organization &apos;Contoso&apos; -Country &apos;US&apos;</dev:code>
<dev:remarks><maml:para>Creates a self-signed root valid for ten years.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificateAuthority -Name &apos;issuing-ca&apos; -Type Intermediate -ParentCaId $Root.Id -CommonName &apos;Contoso Issuing Certificate Authority&apos; -KeyAlgorithm &apos;EC_secp384r1&apos;</dev:code>
<dev:remarks><maml:para>Creates a subordinate, signs it with the root, and imports the signed certificate so it can issue immediately.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificateAuthority</command:name>
<maml:description><maml:para>Renames an internal Infisical certificate authority or changes its status.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificateAuthority</command:noun>
</command:details>
<maml:description>
<maml:para>Updates the name or status of an internal certificate authority. Infisical&apos;s update schema accepts only these two fields; subject, key algorithm, and validity are fixed when the authority is created. Supply -PassThru to emit the updated record.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Disabling an authority stops it issuing without deleting it or the certificates it has already signed. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificateAuthority -CaId $Ca.Id -Status disabled</dev:code>
<dev:remarks><maml:para>Stops the authority issuing new certificates.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificateAuthority -CaId $Ca.Id -Name &apos;retired-issuing-ca&apos; -PassThru</dev:code>
<dev:remarks><maml:para>Renames the authority and emits the updated record.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificateAuthority</command:name>
<maml:description><maml:para>Deletes an internal Infisical certificate authority.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificateAuthority</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes an internal certificate authority from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. Certificates already issued by the authority stop chaining to a known issuer once it is gone, and any subordinate beneath it is orphaned. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificateAuthority -CaId $Ca.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the authority without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificateAuthority -Kind Internal | Where-Object {($_.Status -eq &apos;disabled&apos;)} | Remove-InfisicalCertificateAuthority</dev:code>
<dev:remarks><maml:para>Removes every disabled authority, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificatePolicy</command:name>
<maml:description><maml:para>Creates an Infisical certificate policy that constrains what a profile may issue.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificatePolicy</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a certificate policy: the constraints a certificate profile issues within. Subject attributes, subject alternative names, key usages, and extended key usages are each expressed as allowed, required, and denied sets, supplied as dictionaries so the nested shape stays readable. -MaxValidity caps certificate lifetime, -KeyAlgorithm and -SignatureAlgorithm restrict the cryptography. A constraint that is not supplied leaves that dimension unconstrained, which is what fleet enrollment needs so each machine can present its own name.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Constraint values use Infisical&apos;s snake_case names: digital_signature, key_encipherment, server_auth, client_auth, code_signing, common_name, dns_name, ip_address. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalCertificatePolicy -Name &apos;server-auth&apos; -MaxValidity &apos;90d&apos; -KeyAlgorithm &apos;RSA_2048&apos;,&apos;EC_secp384r1&apos; -KeyUsage @{ Required = @(&apos;digital_signature&apos;,&apos;key_encipherment&apos;) } -ExtendedKeyUsage @{ Required = @(&apos;server_auth&apos;,&apos;client_auth&apos;) }</dev:code>
<dev:remarks><maml:para>Creates a policy for server and client authentication, leaving subject and SANs unconstrained.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificatePolicy -Name &apos;code-signing&apos; -MaxValidity &apos;365d&apos; -ExtendedKeyUsage @{ Required = @(&apos;code_signing&apos;); Denied = @(&apos;server_auth&apos;,&apos;client_auth&apos;) } -SubjectAlternativeName @(@{ Type = &apos;dns_name&apos;; Allowed = @(&apos;*.contoso.com&apos;) })</dev:code>
<dev:remarks><maml:para>Creates a code signing policy that forbids TLS usage and restricts DNS names to one suffix.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificatePolicy</command:name>
<maml:description><maml:para>Updates an Infisical certificate policy.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificatePolicy</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a certificate policy. Only the constraints supplied on the command line are sent; anything omitted keeps its stored value. Supply -PassThru to emit the updated policy.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Changing a policy affects every profile bound to it, and therefore every future certificate those profiles issue. Certificates already issued are unaffected. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificatePolicy -PolicyId $Policy.Id -MaxValidity &apos;30d&apos;</dev:code>
<dev:remarks><maml:para>Shortens the maximum lifetime, leaving every other constraint as it was.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificatePolicy -PolicyId $Policy.Id -ExtendedKeyUsage @{ Required = @(&apos;server_auth&apos;) } -PassThru</dev:code>
<dev:remarks><maml:para>Narrows the extended key usage and emits the updated policy.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificatePolicy</command:name>
<maml:description><maml:para>Deletes an Infisical certificate policy.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificatePolicy</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a certificate policy from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. A profile bound to the policy cannot issue once it is gone, so remove or repoint dependent profiles first. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificatePolicy -PolicyId $Policy.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the policy without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificatePolicy | Where-Object {($_.Name -like &apos;test-*&apos;)} | Remove-InfisicalCertificatePolicy</dev:code>
<dev:remarks><maml:para>Removes every policy whose name begins with test-, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificateProfile</command:name>
<maml:description><maml:para>Creates an Infisical certificate profile that binds an issuing authority to a policy.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificateProfile</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a certificate profile: the object Request-InfisicalCertificate -CertificateProfileId issues against. A profile binds an issuing certificate authority to a certificate policy and exposes it for one enrollment type. -Slug accepts lowercase letters, numbers, and hyphens. -EnrollmentConfig carries the settings for the chosen -EnrollmentType, so EST, ACME, and SCEP settings all arrive through one parameter; for the default api type, -AutoRenew and -RenewBeforeDays are folded into it.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Profile issuance is the only path that does not consult the issuing authority&apos;s direct-issuance flag, so a profile issues successfully against an authority whose EnableDirectIssuance is False. Unlike a PKI subscriber, a profile accepts a per-request common name, which is what makes it suitable for fleet enrollment. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalCertificateProfile -Slug &apos;server-auth&apos; -CertificatePolicyId $Policy.Id -CaId $Ca.Id</dev:code>
<dev:remarks><maml:para>Creates an API enrollment profile bound to a policy and issuing authority.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificateProfile -Slug &apos;workload&apos; -CertificatePolicyId $Policy.Id -CaId $Ca.Id -AutoRenew -RenewBeforeDays 14 -Defaults @{ ttlDays = 90 }</dev:code>
<dev:remarks><maml:para>Creates a profile that renews issued certificates fourteen days before expiry and defaults to a ninety day lifetime.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificateProfile</command:name>
<maml:description><maml:para>Updates an Infisical certificate profile.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificateProfile</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a certificate profile. Only the values supplied on the command line are sent; anything omitted keeps its stored value, including the enrollment type unless -EnrollmentType is passed explicitly. Supply -PassThru to emit the updated profile.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Repointing a profile at a different policy or issuing authority changes what future requests produce. Because certificate reuse is scoped by profile, Request-InfisicalCertificate keeps reusing certificates the profile issued previously until they fall inside their renewal window. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificateProfile -ProfileId $Profile.Id -CertificatePolicyId $NewPolicy.Id</dev:code>
<dev:remarks><maml:para>Repoints the profile at a different policy.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificateProfile -ProfileId $Profile.Id -AutoRenew -RenewBeforeDays 7 -PassThru</dev:code>
<dev:remarks><maml:para>Enables automatic renewal seven days before expiry and emits the updated profile.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificateProfile</command:name>
<maml:description><maml:para>Deletes an Infisical certificate profile.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificateProfile</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a certificate profile from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. Any script requesting certificates through the profile fails once it is gone, and the profile is detached from every application that referenced it. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificateProfile -ProfileId $Profile.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the profile without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificateProfile -ApplicationId $Application.Id | Remove-InfisicalCertificateProfile</dev:code>
<dev:remarks><maml:para>Removes every profile attached to an application, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalCertificateApplication</command:name>
<maml:description><maml:para>Creates an Infisical certificate application to group profiles and certificates.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalCertificateApplication</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a certificate application: the grouping the Infisical console presents profiles, members, and certificates under, and the scope Get-InfisicalCertificateProfile -ApplicationId and Get-InfisicalCertificate -ApplicationId filter by. Certificate profiles can be attached at creation with -ProfileId.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Applications are served only from the organization&apos;s active Certificate Manager project. Creating one in any other cert-manager project fails, which is why -ProjectId resolves to the active project when it is not supplied. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalCertificateApplication -Name &apos;platform&apos; -Description &apos;Endpoint and workload certificates&apos;</dev:code>
<dev:remarks><maml:para>Creates an empty application.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalCertificateApplication -Name &apos;platform&apos; -ProfileId $ServerProfile.Id, $CodeSigningProfile.Id</dev:code>
<dev:remarks><maml:para>Creates an application with two profiles already attached.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalCertificateApplication</command:name>
<maml:description><maml:para>Renames an Infisical certificate application or changes which profiles it holds.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalCertificateApplication</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a certificate application. -Name and -Description change the record; -AddProfileId and -RemoveProfileId change which certificate profiles the application groups. The record and its profile attachments are separate endpoints, so supplying only profile parameters skips the record update entirely. Supply -PassThru to emit the updated application.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Detaching a profile does not delete it; the profile continues to exist and issue, it is simply no longer grouped under the application. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalCertificateApplication -ApplicationId $Application.Id -AddProfileId $Profile.Id</dev:code>
<dev:remarks><maml:para>Attaches a profile to the application.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalCertificateApplication -ApplicationId $Application.Id -Name &apos;endpoint-management&apos; -RemoveProfileId $Old.Id -PassThru</dev:code>
<dev:remarks><maml:para>Renames the application, detaches a profile, and emits the updated record.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalCertificateApplication</command:name>
<maml:description><maml:para>Deletes an Infisical certificate application.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalCertificateApplication</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a certificate application from a Certificate Manager project. -PassThru emits the removed identifier for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. The profiles the application grouped are not deleted, but scripts that locate a profile by application can no longer find it. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalCertificateApplication -ApplicationId $Application.Id -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the application without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalCertificateApplication | Where-Object {($_.CertificateCount -eq 0)} | Remove-InfisicalCertificateApplication</dev:code>
<dev:remarks><maml:para>Removes every application holding no certificates, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>New-InfisicalPkiSubscriber</command:name>
<maml:description><maml:para>Creates an Infisical PKI subscriber, a named enrollment identity with a fixed common name.</maml:para></maml:description>
<command:verb>New</command:verb>
<command:noun>InfisicalPkiSubscriber</command:noun>
</command:details>
<maml:description>
<maml:para>Creates a PKI subscriber: a named enrollment identity that pins one common name, an allowlist of subject alternative names, a lifetime, and the permitted key usages, so a request carries only a certificate signing request. -CommonName is the identity the subscriber issues for, and -SubjectAlternativeName is an allowlist rather than a default.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>A subscriber is a single identity, not a template. Infisical rejects any request whose certificate signing request names a different common name, and rejects any subject alternative name outside the allowlist, so enrolling many machines through subscribers means one subscriber per machine. Use a certificate profile for fleet enrollment. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>New-InfisicalPkiSubscriber -Name &apos;web01&apos; -CommonName &apos;WEB01.contoso.com&apos; -CaId $Ca.Id -Ttl &apos;90d&apos;</dev:code>
<dev:remarks><maml:para>Creates a subscriber for one host.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>New-InfisicalPkiSubscriber -Name &apos;web01&apos; -CommonName &apos;WEB01.contoso.com&apos; -CaId $Ca.Id -Ttl &apos;90d&apos; -SubjectAlternativeName &apos;WEB01&apos;,&apos;WEB01.contoso.com&apos; -ExtendedKeyUsage &apos;serverAuth&apos;,&apos;clientAuth&apos;</dev:code>
<dev:remarks><maml:para>Creates a subscriber that also permits two subject alternative names and restricts extended key usage.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Set-InfisicalPkiSubscriber</command:name>
<maml:description><maml:para>Updates an Infisical PKI subscriber.</maml:para></maml:description>
<command:verb>Set</command:verb>
<command:noun>InfisicalPkiSubscriber</command:noun>
</command:details>
<maml:description>
<maml:para>Updates a PKI subscriber, addressed by its current -Name. Only the values supplied on the command line are sent; anything omitted keeps its stored value. -NewName renames the subscriber. Supply -PassThru to emit the updated record.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Changing -CommonName changes the identity the subscriber issues for, so any script signing against it must present a matching certificate signing request afterwards. Honors -WhatIf and -Confirm.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Set-InfisicalPkiSubscriber -Name &apos;web01&apos; -Ttl &apos;30d&apos;</dev:code>
<dev:remarks><maml:para>Shortens the lifetime of certificates issued for the subscriber.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Set-InfisicalPkiSubscriber -Name &apos;web01&apos; -SubjectAlternativeName &apos;WEB01&apos;,&apos;WEB01.contoso.com&apos;,&apos;www.contoso.com&apos; -PassThru</dev:code>
<dev:remarks><maml:para>Extends the permitted subject alternative names and emits the updated subscriber.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
<command:command xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:command="http://schemas.microsoft.com/maml/dev/command/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10">
<command:details>
<command:name>Remove-InfisicalPkiSubscriber</command:name>
<maml:description><maml:para>Deletes an Infisical PKI subscriber.</maml:para></maml:description>
<command:verb>Remove</command:verb>
<command:noun>InfisicalPkiSubscriber</command:noun>
</command:details>
<maml:description>
<maml:para>Deletes a PKI subscriber from a Certificate Manager project, addressed by name. -PassThru emits the removed name for logging.</maml:para>
</maml:description>
<maml:alertSet>
<maml:title>Notes</maml:title>
<maml:alert>
<maml:para>Destructive. Any script signing through the subscriber fails once it is gone. Certificates already issued are unaffected. High ConfirmImpact prompts unless -Confirm:$False is supplied.</maml:para>
</maml:alert>
</maml:alertSet>
<command:examples>
<command:example>
<maml:title>EXAMPLE 1</maml:title>
<dev:code>Remove-InfisicalPkiSubscriber -Name &apos;web01&apos; -Confirm:$False</dev:code>
<dev:remarks><maml:para>Deletes the subscriber without prompting.</maml:para></dev:remarks>
</command:example>
<command:example>
<maml:title>EXAMPLE 2</maml:title>
<dev:code>Get-InfisicalPkiSubscriber | Where-Object {($_.Status -ne &apos;active&apos;)} | Remove-InfisicalPkiSubscriber</dev:code>
<dev:remarks><maml:para>Removes every inactive subscriber, prompting for each.</maml:para></dev:remarks>
</command:example>
</command:examples>
</command:command>
</helpItems>