Skip to main content

CertManagerApplicationProfile

Resource CertManagerApplicationProfile in pulumi-infisical.
7 min read

Resource CertManagerApplicationProfile in pulumi-infisical.

Pulumi type: infisical:index/certManagerApplicationProfile:CertManagerApplicationProfile.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
acmeConfigCertManagerApplicationProfileAcmeConfig (input)noEnable the ACME enrollment method. Omit the block to disable ACME enrollment.
apiConfigCertManagerApplicationProfileApiConfig (input)noEnable the API enrollment method. Omit the block to disable API enrollment.
applicationIdstringyesThe ID of the Certificate Manager application
estConfigCertManagerApplicationProfileEstConfig (input)noEnable the EST enrollment method. Omit the block to disable EST enrollment.
profileIdstringyesThe ID of the certificate profile to attach
scepConfigCertManagerApplicationProfileScepConfig (input)noEnable the SCEP enrollment method. Omit the block to disable SCEP enrollment.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
acmeConfigCertManagerApplicationProfileAcmeConfig (output)noEnable the ACME enrollment method. Omit the block to disable ACME enrollment.
apiConfigCertManagerApplicationProfileApiConfig (output)noEnable the API enrollment method. Omit the block to disable API enrollment.
applicationIdstringnoThe ID of the Certificate Manager application
estConfigCertManagerApplicationProfileEstConfig (output)noEnable the EST enrollment method. Omit the block to disable EST enrollment.
profileIdstringnoThe ID of the certificate profile to attach
scepConfigCertManagerApplicationProfileScepConfig (output)noEnable the SCEP enrollment method. Omit the block to disable SCEP enrollment.

CertManagerApplicationProfileAcmeConfig (input)#

Input object CertManagerApplicationProfileAcmeConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
directoryUrlstringnoThe ACME directory URL clients should use.
eabKidstringnoExternal Account Binding key identifier. Populated on create and on import; routine refreshes don't re-fetch it. Rotated only by the explicit rotate endpoint, never by Terraform.
eabSecretstringnoExternal Account Binding shared secret. Populated on create and on import; routine refreshes don't re-fetch it. Rotated only by the explicit rotate endpoint, never by Terraform.
skipDnsOwnershipVerificationbooleannoSkip DNS ownership verification. Defaults to false.
skipEabBindingbooleannoSkip External Account Binding. Defaults to false. Cannot be set to true at the same time as skip_dns_ownership_verification.

CertManagerApplicationProfileApiConfig (input)#

Input object CertManagerApplicationProfileApiConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
autoRenewbooleannoWhether to automatically renew certificates. Defaults to false when omitted.
renewBeforeDaysnumbernoNumber of days before expiration to renew (1-30). Defaults to 7 when omitted.

CertManagerApplicationProfileEstConfig (input)#

Input object CertManagerApplicationProfileEstConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
caChainstringnoPEM-encoded CA chain used for bootstrap CA validation (only honored when disableBootstrapCaValidation is false).
disableBootstrapCaValidationbooleannoWhether to disable bootstrap CA validation. Defaults to false.
endpointUrlstringnoThe EST endpoint URL clients should use.
passphrasestringyesEST passphrase used to authorize certificate requests.

CertManagerApplicationProfileScepConfig (input)#

Input object CertManagerApplicationProfileScepConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowCertBasedRenewalbooleannoAllow certificate-based renewal. Defaults to true.
challengeEndpointUrlstringnoThe SCEP dynamic challenge endpoint URL (only set when challengeType is dynamic).
challengePasswordstringnoStatic-mode SCEP challenge password (min 8 chars). Required when challengeType is static.
challengeTypestringnoSCEP challenge type. Supported values: static, dynamic. Defaults to static.
dynamicChallengeExpiryMinutesnumbernoExpiry of a dynamic challenge in minutes (1-1440). Only used when challengeType is dynamic.
dynamicChallengeMaxPendingnumbernoMaximum pending dynamic challenges (1-1000). Only used when challengeType is dynamic.
includeCaCertInResponsebooleannoInclude the issuing CA certificate in SCEP responses. Defaults to true.
raCertExpiresAtstringnoISO-8601 timestamp when the RA certificate expires.
raCertificatePemstringnoThe PEM-encoded RA certificate used by the SCEP service.
scepEndpointUrlstringnoThe SCEP endpoint URL clients should use.
signRaWithCabooleannoSign the RA certificate with the profile's CA instead of self-signing it, so it chains to the CA root. Required by strict clients such as Apple and Microsoft Intune. Only supported for internal CAs. Cannot be changed once SCEP enrollment is configured. To change it, remove scepConfig(or the whole resource) to disable SCEP enrollment in one apply, then add scepConfig back with the new value in a subsequent apply. Defaults to false.

CertManagerApplicationProfileAcmeConfig (output)#

Output object CertManagerApplicationProfileAcmeConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
directoryUrlstringyesThe ACME directory URL clients should use.
eabKidstringyesExternal Account Binding key identifier. Populated on create and on import; routine refreshes don't re-fetch it. Rotated only by the explicit rotate endpoint, never by Terraform.
eabSecretstringyesExternal Account Binding shared secret. Populated on create and on import; routine refreshes don't re-fetch it. Rotated only by the explicit rotate endpoint, never by Terraform.
skipDnsOwnershipVerificationbooleanyesSkip DNS ownership verification. Defaults to false.
skipEabBindingbooleanyesSkip External Account Binding. Defaults to false. Cannot be set to true at the same time as skip_dns_ownership_verification.

CertManagerApplicationProfileApiConfig (output)#

Output object CertManagerApplicationProfileApiConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
autoRenewbooleanyesWhether to automatically renew certificates. Defaults to false when omitted.
renewBeforeDaysnumberyesNumber of days before expiration to renew (1-30). Defaults to 7 when omitted.

CertManagerApplicationProfileEstConfig (output)#

Output object CertManagerApplicationProfileEstConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
caChainstringnoPEM-encoded CA chain used for bootstrap CA validation (only honored when disableBootstrapCaValidation is false).
disableBootstrapCaValidationbooleanyesWhether to disable bootstrap CA validation. Defaults to false.
endpointUrlstringyesThe EST endpoint URL clients should use.
passphrasestringyesEST passphrase used to authorize certificate requests.

CertManagerApplicationProfileScepConfig (output)#

Output object CertManagerApplicationProfileScepConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowCertBasedRenewalbooleanyesAllow certificate-based renewal. Defaults to true.
challengeEndpointUrlstringyesThe SCEP dynamic challenge endpoint URL (only set when challengeType is dynamic).
challengePasswordstringnoStatic-mode SCEP challenge password (min 8 chars). Required when challengeType is static.
challengeTypestringyesSCEP challenge type. Supported values: static, dynamic. Defaults to static.
dynamicChallengeExpiryMinutesnumberyesExpiry of a dynamic challenge in minutes (1-1440). Only used when challengeType is dynamic.
dynamicChallengeMaxPendingnumberyesMaximum pending dynamic challenges (1-1000). Only used when challengeType is dynamic.
includeCaCertInResponsebooleanyesInclude the issuing CA certificate in SCEP responses. Defaults to true.
raCertExpiresAtstringyesISO-8601 timestamp when the RA certificate expires.
raCertificatePemstringyesThe PEM-encoded RA certificate used by the SCEP service.
scepEndpointUrlstringyesThe SCEP endpoint URL clients should use.
signRaWithCabooleanyesSign the RA certificate with the profile's CA instead of self-signing it, so it chains to the CA root. Required by strict clients such as Apple and Microsoft Intune. Only supported for internal CAs. Cannot be changed once SCEP enrollment is configured. To change it, remove scepConfig(or the whole resource) to disable SCEP enrollment in one apply, then add scepConfig back with the new value in a subsequent apply. Defaults to false.