Correct issuance-path guidance: profiles for fleets, subscribers are per-identity
The subscriber guidance shipped in #18 was wrong for fleet enrollment. signSubscriberCert rejects any CSR whose CN differs from the subscriber's commonName, and allowlists the subscriber's subjectAlternativeNames, so a subscriber is a single named identity rather than a template. Enrolling N machines through subscribers would require N subscribers. Certificate profiles are the correct path: they accept a per-request common name constrained by policy allowed/required/denied lists, and profile issuance is the only path that skips the CA direct-issuance gate (!isFromProfile && !ca.enableDirectIssuance && !certificateTemplate), so a profile issues against a CA whose EnableDirectIssuance is False. Also documents that enableDirectIssuance cannot be changed after CA creation: it appears in no Infisical create or update schema (the generic CA schemas accept only name and status). Migration 20250521110635_add-external-ca-pki.ts renamed requireTemplateForIssuance to enableDirectIssuance and inverted every existing value, so CAs that previously required a template now read False permanently. The remedies are a profile, or a new CA (column defaults to true). README end-to-end example switched from subscriber to profile issuance, and the issuance-path table now leads with whether the common name varies per request. Cmdlet help for Request-InfisicalCertificate and Get-InfisicalCertificateAuthority updated to match. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,6 +6,12 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/) loos
|
||||
|
||||
## Unreleased
|
||||
|
||||
## 2026.07.30.2239
|
||||
|
||||
- Build produced from commit f62b3e90b1b1.
|
||||
|
||||
## Unreleased (carried forward)
|
||||
|
||||
## 2026.07.30.2151
|
||||
|
||||
- Build produced from commit 14c8c4f3845b.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
@{
|
||||
RootModule = 'PSInfisicalAPI.psm1'
|
||||
ModuleVersion = '2026.07.30.2151'
|
||||
ModuleVersion = '2026.07.30.2239'
|
||||
GUID = 'b8a2f3d4-7c51-4d2f-9e6a-1f0c8b3d4e51'
|
||||
Author = 'Grace Solutions'
|
||||
CompanyName = 'Grace Solutions'
|
||||
@@ -74,7 +74,7 @@
|
||||
LicenseUri = 'https://www.gnu.org/licenses/agpl-3.0.html'
|
||||
ProjectUri = 'https://prod.git.gracesolution.info/gsadmin/PSInfisicalAPI'
|
||||
ReleaseNotes = 'See CHANGELOG.md in the project repository for release history.'
|
||||
CommitHash = '14c8c4f3845b'
|
||||
CommitHash = 'f62b3e90b1b1'
|
||||
}
|
||||
}
|
||||
}
|
||||
Binary file not shown.
@@ -1066,7 +1066,7 @@ $RemoveInfisicalTagResult = Remove-InfisicalTag @RemoveInfisicalTagParameters</d
|
||||
<maml:alertSet>
|
||||
<maml:title>Notes</maml:title>
|
||||
<maml:alert>
|
||||
<maml:para>ByID retrieval currently always resolves against the internal CA endpoint. CA Ids returned here are the values to pass on -CertificateAuthorityId to Request-InfisicalCertificate. The Type property distinguishes 'internal' from 'acme' when -Kind Any is used. Only CAs whose EnableDirectIssuance property is True can sign a CSR through -CertificateAuthorityId; the others require a subscriber or certificate profile instead.</maml:para>
|
||||
<maml:para>ByID retrieval currently always resolves against the internal CA endpoint. CA Ids returned here are the values to pass on -CertificateAuthorityId to Request-InfisicalCertificate. The Type property distinguishes 'internal' from 'acme' when -Kind Any is used. Only CAs whose EnableDirectIssuance property is True can sign a CSR through -CertificateAuthorityId; the others must issue through Request-InfisicalCertificate -CertificateProfileId, which bypasses that check. EnableDirectIssuance is fixed at CA creation and appears in no Infisical update schema, so it cannot be toggled afterwards; a CA migrated from the older requireTemplateForIssuance column reads False permanently.</maml:para>
|
||||
</maml:alert>
|
||||
</maml:alertSet>
|
||||
<command:examples>
|
||||
@@ -1281,7 +1281,9 @@ $GetInfisicalCertificatePolicyResult = Get-InfisicalCertificatePolicy @GetInfisi
|
||||
<maml:title>Notes</maml:title>
|
||||
<maml:alert>
|
||||
<maml:para>Default -PrivateKeyProtection is 'LocalOnly': the leaf is loaded into memory without persisting the private key and PrivateKeyPem is scrubbed from the emitted result unless -PrivateKeyPath or an explicit -KeyStorageFlags binding overrides it. The reuse path completes its chain from the Infisical bundle when local stores are incomplete; pass -LocalChainOnly to suppress that fetch entirely.</maml:para>
|
||||
<maml:para>-CertificateAuthorityId only works against a CA that permits direct issuance (Get-InfisicalCertificateAuthority reports this as EnableDirectIssuance). The cmdlet resolves the issuer and validates this before generating a keypair, naming the subscriber, CA, or profile it will use on the verbose stream and in the -WhatIf target. There is no -CertificateTemplateId parameter because Infisical's REST API exposes no template-based issuance route; when the API asks for 'a certificate template or subscriber', supply -PkiSubscriberSlug or -CertificateProfileId, or enable direct issuance on the CA.</maml:para>
|
||||
<maml:para>Choose the parameter set by whether the common name varies per request. -CertificateProfileId and -CertificateAuthorityId both accept a per-request common name and suit fleet enrollment; -PkiSubscriberSlug does not, because Infisical rejects any CSR whose CN differs from the subscriber's ('Common name (CN) in the CSR does not match the subscriber's common name') and allowlists the subscriber's subjectAlternativeNames. A subscriber is a single named identity, so enrolling many machines through subscribers requires one subscriber per machine.</maml:para>
|
||||
<maml:para>-CertificateAuthorityId only works against a CA that permits direct issuance (Get-InfisicalCertificateAuthority reports this as EnableDirectIssuance). The cmdlet resolves the issuer and validates this before generating a keypair, naming the subscriber, CA, or profile it will use on the verbose stream and in the -WhatIf target. Profile issuance is the only path that ignores that flag, so -CertificateProfileId works against a CA whose EnableDirectIssuance is False. Note that enableDirectIssuance appears in no Infisical create or update schema, so it cannot be changed through the API or UI after the CA exists.</maml:para>
|
||||
<maml:para>There is no -CertificateTemplateId parameter because Infisical's REST API exposes no template-based issuance route; when the API asks for 'a certificate template or subscriber', supply -CertificateProfileId or -PkiSubscriberSlug, or use a CA that allows direct issuance.</maml:para>
|
||||
<maml:para>-CommonName takes the bare value ('web01.contoso.com'), not an RDN; a leading 'CN=' is stripped because the CSR builder adds the prefix itself. -DnsName accepts the mixed output of Get-InfisicalSANList: IP literals in that list are emitted as iPAddress SAN entries rather than dNSName entries.</maml:para>
|
||||
</maml:alert>
|
||||
</maml:alertSet>
|
||||
|
||||
@@ -1066,7 +1066,7 @@ $RemoveInfisicalTagResult = Remove-InfisicalTag @RemoveInfisicalTagParameters</d
|
||||
<maml:alertSet>
|
||||
<maml:title>Notes</maml:title>
|
||||
<maml:alert>
|
||||
<maml:para>ByID retrieval currently always resolves against the internal CA endpoint. CA Ids returned here are the values to pass on -CertificateAuthorityId to Request-InfisicalCertificate. The Type property distinguishes 'internal' from 'acme' when -Kind Any is used. Only CAs whose EnableDirectIssuance property is True can sign a CSR through -CertificateAuthorityId; the others require a subscriber or certificate profile instead.</maml:para>
|
||||
<maml:para>ByID retrieval currently always resolves against the internal CA endpoint. CA Ids returned here are the values to pass on -CertificateAuthorityId to Request-InfisicalCertificate. The Type property distinguishes 'internal' from 'acme' when -Kind Any is used. Only CAs whose EnableDirectIssuance property is True can sign a CSR through -CertificateAuthorityId; the others must issue through Request-InfisicalCertificate -CertificateProfileId, which bypasses that check. EnableDirectIssuance is fixed at CA creation and appears in no Infisical update schema, so it cannot be toggled afterwards; a CA migrated from the older requireTemplateForIssuance column reads False permanently.</maml:para>
|
||||
</maml:alert>
|
||||
</maml:alertSet>
|
||||
<command:examples>
|
||||
@@ -1281,7 +1281,9 @@ $GetInfisicalCertificatePolicyResult = Get-InfisicalCertificatePolicy @GetInfisi
|
||||
<maml:title>Notes</maml:title>
|
||||
<maml:alert>
|
||||
<maml:para>Default -PrivateKeyProtection is 'LocalOnly': the leaf is loaded into memory without persisting the private key and PrivateKeyPem is scrubbed from the emitted result unless -PrivateKeyPath or an explicit -KeyStorageFlags binding overrides it. The reuse path completes its chain from the Infisical bundle when local stores are incomplete; pass -LocalChainOnly to suppress that fetch entirely.</maml:para>
|
||||
<maml:para>-CertificateAuthorityId only works against a CA that permits direct issuance (Get-InfisicalCertificateAuthority reports this as EnableDirectIssuance). The cmdlet resolves the issuer and validates this before generating a keypair, naming the subscriber, CA, or profile it will use on the verbose stream and in the -WhatIf target. There is no -CertificateTemplateId parameter because Infisical's REST API exposes no template-based issuance route; when the API asks for 'a certificate template or subscriber', supply -PkiSubscriberSlug or -CertificateProfileId, or enable direct issuance on the CA.</maml:para>
|
||||
<maml:para>Choose the parameter set by whether the common name varies per request. -CertificateProfileId and -CertificateAuthorityId both accept a per-request common name and suit fleet enrollment; -PkiSubscriberSlug does not, because Infisical rejects any CSR whose CN differs from the subscriber's ('Common name (CN) in the CSR does not match the subscriber's common name') and allowlists the subscriber's subjectAlternativeNames. A subscriber is a single named identity, so enrolling many machines through subscribers requires one subscriber per machine.</maml:para>
|
||||
<maml:para>-CertificateAuthorityId only works against a CA that permits direct issuance (Get-InfisicalCertificateAuthority reports this as EnableDirectIssuance). The cmdlet resolves the issuer and validates this before generating a keypair, naming the subscriber, CA, or profile it will use on the verbose stream and in the -WhatIf target. Profile issuance is the only path that ignores that flag, so -CertificateProfileId works against a CA whose EnableDirectIssuance is False. Note that enableDirectIssuance appears in no Infisical create or update schema, so it cannot be changed through the API or UI after the CA exists.</maml:para>
|
||||
<maml:para>There is no -CertificateTemplateId parameter because Infisical's REST API exposes no template-based issuance route; when the API asks for 'a certificate template or subscriber', supply -CertificateProfileId or -PkiSubscriberSlug, or use a CA that allows direct issuance.</maml:para>
|
||||
<maml:para>-CommonName takes the bare value ('web01.contoso.com'), not an RDN; a leading 'CN=' is stripped because the CSR builder adds the prefix itself. -DnsName accepts the mixed output of Get-InfisicalSANList: IP literals in that list are emitted as iPAddress SAN entries rather than dNSName entries.</maml:para>
|
||||
</maml:alert>
|
||||
</maml:alertSet>
|
||||
|
||||
@@ -146,7 +146,9 @@ Disconnect-Infisical
|
||||
|
||||
## End-to-end: request and install a chained certificate
|
||||
|
||||
Connects, selects a `cert-manager` project, sources SANs from `Get-InfisicalSANList`, requests a certificate through a PKI subscriber, installs it (and its chain) into the current-user store, and disconnects. Each call uses a splatted `OrderedDictionary` constructed with `OrdinalIgnoreCase` so parameter names round-trip case-insensitively.
|
||||
Connects, selects a `cert-manager` project, sources SANs from `Get-InfisicalSANList`, requests a certificate through a certificate profile, installs it (and its chain) into the current-user store, and disconnects. Each call uses a splatted `OrderedDictionary` constructed with `OrdinalIgnoreCase` so parameter names round-trip case-insensitively.
|
||||
|
||||
This is the shape to use for **fleet enrollment**, where each machine needs its own common name. See [Choosing an issuance path](#choosing-an-issuance-path) — a PKI subscriber is *not* the right tool for this, because it pins one fixed common name.
|
||||
|
||||
```powershell
|
||||
$ConnectInfisicalParameters = New-Object -TypeName 'System.Collections.Specialized.OrderedDictionary' -ArgumentList ([System.StringComparer]::OrdinalIgnoreCase)
|
||||
@@ -159,20 +161,21 @@ $ConnectInfisicalParameters = New-Object -TypeName 'System.Collections.Specializ
|
||||
|
||||
$Connection = Connect-Infisical @ConnectInfisicalParameters
|
||||
|
||||
$Project = Get-InfisicalProject -Type cert-manager | Where-Object {($_.Name -eq 'Platform')} | Select-Object -First 1
|
||||
$Subscriber = Get-InfisicalPkiSubscriber -ProjectId ($Project.Id) | Select-Object -First 1
|
||||
$SanList = Get-InfisicalSANList
|
||||
$Project = Get-InfisicalProject -Type cert-manager | Where-Object {($_.Name -eq 'Platform')} | Select-Object -First 1
|
||||
$Profile = Get-InfisicalCertificateProfile -ProjectId ($Project.Id) | Select-Object -First 1
|
||||
$SanList = Get-InfisicalSANList
|
||||
|
||||
$RequestInfisicalCertificateParameters = New-Object -TypeName 'System.Collections.Specialized.OrderedDictionary' -ArgumentList ([System.StringComparer]::OrdinalIgnoreCase)
|
||||
$RequestInfisicalCertificateParameters.ProjectId = $Project.Id
|
||||
$RequestInfisicalCertificateParameters.PkiSubscriberSlug = $Subscriber.Name
|
||||
$RequestInfisicalCertificateParameters.CommonName = $Env:ComputerName.ToUpper()
|
||||
$RequestInfisicalCertificateParameters.DnsName = New-Object -TypeName 'System.Collections.Generic.List[System.String]'
|
||||
$RequestInfisicalCertificateParameters.ProjectId = $Project.Id
|
||||
$RequestInfisicalCertificateParameters.CertificateProfileId = $Profile.Id
|
||||
$RequestInfisicalCertificateParameters.CommonName = $Env:ComputerName.ToUpper()
|
||||
$RequestInfisicalCertificateParameters.DnsName = New-Object -TypeName 'System.Collections.Generic.List[System.String]'
|
||||
$RequestInfisicalCertificateParameters.DnsName.AddRange($SanList)
|
||||
$RequestInfisicalCertificateParameters.DnsName.Add('myrecord.mydomain.com')
|
||||
$RequestInfisicalCertificateParameters.Install = $True
|
||||
$RequestInfisicalCertificateParameters.InstallChain = $True
|
||||
$RequestInfisicalCertificateParameters.Verbose = $True
|
||||
$RequestInfisicalCertificateParameters.Ttl = '90d'
|
||||
$RequestInfisicalCertificateParameters.Install = $True
|
||||
$RequestInfisicalCertificateParameters.InstallChain = $True
|
||||
$RequestInfisicalCertificateParameters.Verbose = $True
|
||||
|
||||
$Certificate = Request-InfisicalCertificate @RequestInfisicalCertificateParameters
|
||||
|
||||
@@ -181,20 +184,28 @@ $Null = Disconnect-Infisical -Verbose
|
||||
|
||||
### Choosing an issuance path
|
||||
|
||||
`Request-InfisicalCertificate` has three mutually exclusive issuance parameter sets. Which one works depends on how the project is configured in Infisical:
|
||||
`Request-InfisicalCertificate` has three mutually exclusive issuance parameter sets. The deciding question is **whether the common name varies per request**:
|
||||
|
||||
| Parameter | Use when |
|
||||
| -------------------------- | ------------------------------------------------------------------------------------------ |
|
||||
| `-PkiSubscriberSlug` | The project defines PKI subscribers (`Get-InfisicalPkiSubscriber`). Preferred for most setups. |
|
||||
| `-CertificateProfileId` | The project issues through certificate profiles (`Get-InfisicalCertificateProfile`). |
|
||||
| `-CertificateAuthorityId` | Signing straight against a CA. Requires **direct issuance** to be enabled on that CA. |
|
||||
| Parameter | Common name | Use when |
|
||||
| -------------------------- | ------------------------------------ | ------------------------------------------------------------------------ |
|
||||
| `-CertificateProfileId` | **Per request**, constrained by policy | Fleet enrollment — many machines, each with its own CN. Works on any CA. |
|
||||
| `-CertificateAuthorityId` | **Per request**, unconstrained | Fleet enrollment where no policy is wanted. Needs direct issuance on the CA. |
|
||||
| `-PkiSubscriberSlug` | **Fixed** by the subscriber record | One named identity — a specific service or host, provisioned in advance. |
|
||||
|
||||
There is no `-CertificateTemplateId` parameter. Infisical's REST API exposes no template-based issuance route — templates are consumed internally by EST and subscribers — so when the API says *"Certificate template or subscriber is required for issuance"*, the reachable answers are a subscriber, a profile, or enabling direct issuance.
|
||||
**A PKI subscriber is a per-identity object, not a fleet template.** `signSubscriberCert` rejects any CSR whose CN differs from the subscriber's:
|
||||
|
||||
```text
|
||||
Common name (CN) in the CSR does not match the subscriber's common name
|
||||
```
|
||||
|
||||
It also allowlists SANs — every `dNSName`/`email` SAN in the CSR must appear in the subscriber's `subjectAlternativeNames` — and requires CSR key usages to be a subset of the subscriber's. (IP SANs are not covered by that check.) Enrolling *N* machines through subscribers therefore means creating *N* subscribers. Prefer a profile.
|
||||
|
||||
There is no `-CertificateTemplateId` parameter. Infisical's REST API exposes no template-based issuance route — templates are consumed internally by EST and subscribers — so when the API says *"Certificate template or subscriber is required for issuance"*, the reachable answers are a profile, a subscriber, or direct issuance.
|
||||
|
||||
The cmdlet resolves and reports the issuer before generating a keypair, so `-Verbose` tells you exactly what will sign the request:
|
||||
|
||||
```text
|
||||
VERBOSE: [...] - [Information] - [RequestInfisicalCertificateCmdlet] - Issuing via PKI subscriber 'web-tier' in project '2122628e-...'.
|
||||
VERBOSE: [...] - [Information] - [RequestInfisicalCertificateCmdlet] - Issuing via certificate profile 'a1b2c3d4-...' in project '2122628e-...'.
|
||||
VERBOSE: [...] - [Information] - [RequestInfisicalCertificateCmdlet] - Issuing directly via certificate authority 'intermediate-ca' (bf661d78-...); direct issuance is enabled.
|
||||
```
|
||||
|
||||
@@ -203,34 +214,52 @@ VERBOSE: [...] - [Information] - [RequestInfisicalCertificateCmdlet] - Issuing d
|
||||
```powershell
|
||||
Request-InfisicalCertificate @RequestInfisicalCertificateParameters -WhatIf
|
||||
# What if: Performing the operation "Request new certificate" on target
|
||||
# "PKI subscriber 'web-tier' for CN=WEB01".
|
||||
# "certificate profile 'a1b2c3d4-...' for CN=WEB01".
|
||||
```
|
||||
|
||||
#### Discovering subscribers
|
||||
#### Discovering profiles (recommended)
|
||||
|
||||
A subscriber is a named enrollment identity that pins the CA, TTL, key usages, and SAN policy, so the request carries only a CSR. List what a project offers:
|
||||
A certificate profile binds a CA to a certificate policy. The policy constrains the subject, key usages, and extended key usages with `allowed`/`required`/`denied` lists, so the common name still varies per request while staying inside guardrails.
|
||||
|
||||
```powershell
|
||||
Get-InfisicalCertificateProfile -ProjectId ($Project.Id) | Format-Table Id, Name, CaId
|
||||
Get-InfisicalCertificatePolicy -ProjectId ($Project.Id) | Format-Table Id, Name
|
||||
```
|
||||
|
||||
Profile issuance is the only path that does **not** consult the CA's direct-issuance flag — the service short-circuits it:
|
||||
|
||||
```ts
|
||||
if (!isFromProfile && !ca.enableDirectIssuance && !certificateTemplate) { throw ... }
|
||||
```
|
||||
|
||||
So a profile issues successfully against a CA whose `EnableDirectIssuance` is `False`. If a project has no profiles, create a policy then a profile under **Certificate Management** in the Infisical UI.
|
||||
|
||||
#### Discovering subscribers
|
||||
|
||||
```powershell
|
||||
Get-InfisicalPkiSubscriber -ProjectId ($Project.Id) |
|
||||
Format-Table Name, CommonName, Status, Ttl, CaId
|
||||
```
|
||||
|
||||
Pass the subscriber's `Name` to `-PkiSubscriberSlug`. Because the subscriber owns the lifetime and usage policy, `-Ttl`, `-KeyUsage`, and `-ExtendedKeyUsage` are not accepted on this parameter set — set them on the subscriber in Infisical instead.
|
||||
Pass the subscriber's `Name` to `-PkiSubscriberSlug`, and set `-CommonName` to exactly that subscriber's `CommonName`. Because the subscriber owns the lifetime and usage policy, `-Ttl`, `-KeyUsage`, and `-ExtendedKeyUsage` are not accepted on this parameter set — set them on the subscriber in Infisical instead.
|
||||
|
||||
If the project has no subscribers, either create one (**Certificate Management > Subscribers > Add Subscriber**) or use one of the other two paths.
|
||||
An empty result means the project has no subscribers; create one under **Certificate Management > Subscribers**. This module is read-only for subscribers, so creation is UI or raw API (`POST /api/v1/pki/subscribers`).
|
||||
|
||||
#### Enabling direct issuance on a CA
|
||||
#### Direct issuance on a CA
|
||||
|
||||
Direct issuance lets a CA sign a bare CSR with no subscriber or template in front of it. It is a per-CA setting, and Infisical rejects the request with `400 Certificate template or subscriber is required for issuance` when it is off. This module now catches that before building a CSR:
|
||||
Direct issuance lets a CA sign a bare CSR with no profile, subscriber, or template in front of it. When it is off, Infisical rejects the request with `400 Certificate template or subscriber is required for issuance`; this module catches that before building a CSR.
|
||||
|
||||
```text
|
||||
Request-InfisicalCertificate : Certificate authority 'intermediate-ca' (bf661d78-...) has direct issuance
|
||||
disabled, so it cannot sign a CSR on its own. Either enable direct issuance on the CA in Infisical
|
||||
(Certificate Authorities > the CA > Enable Direct Issuance), or issue through a subscriber or profile
|
||||
instead: Request-InfisicalCertificate -PkiSubscriberSlug <name> ... or -CertificateProfileId <id> ...
|
||||
> **There is no UI toggle or API field for this.** `enableDirectIssuance` appears in no create or update schema — the generic CA schemas accept only `name` and `status`. It is set at CA creation (the column defaults to `true`) and is not editable afterwards through the public API.
|
||||
|
||||
A CA can therefore read `False` for a reason that is not obvious. Migration `20250521110635_add-external-ca-pki.ts` renamed the older `requireTemplateForIssuance` column to `enableDirectIssuance` and **inverted** every existing value:
|
||||
|
||||
```ts
|
||||
t.renameColumn("requireTemplateForIssuance", "enableDirectIssuance");
|
||||
...
|
||||
.update({ name: slugifiedName, enableDirectIssuance: !ca.enableDirectIssuance });
|
||||
```
|
||||
|
||||
To turn it on, in the Infisical UI open the `cert-manager` project, go to **Certificate Authorities**, select the CA, and enable **Direct Issuance** in its settings. The setting is surfaced by this module as `EnableDirectIssuance`, so you can confirm it and pick an eligible CA in one step:
|
||||
Any CA created before that migration with "require template for issuance" enabled now reads `EnableDirectIssuance = False` permanently. The options are to **use a profile** (which ignores the flag), or to create a new CA — new CAs default to `true`.
|
||||
|
||||
```powershell
|
||||
Get-InfisicalCertificateAuthority -ProjectId ($Project.Id) -Kind Internal |
|
||||
@@ -244,8 +273,6 @@ $RequestInfisicalCertificateParameters.CertificateAuthorityId = $Ca.Id
|
||||
$RequestInfisicalCertificateParameters.Ttl = '90d' # required by the CA path
|
||||
```
|
||||
|
||||
Prefer a subscriber or profile for routine enrollment: direct issuance bypasses the naming and key-usage constraints those layers enforce. Reserve it for bootstrap or break-glass cases.
|
||||
|
||||
### Subject and SAN handling
|
||||
|
||||
- `-CommonName` takes the bare value (`WEB01.contoso.com`), not an RDN. `CN=WEB01` is accepted and normalized, since the CSR builder adds the `CN=` prefix itself.
|
||||
|
||||
Reference in New Issue
Block a user