# CertManagerCertificatePolicy

> Resource CertManagerCertificatePolicy in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource CertManagerCertificatePolicy in pulumi-infisical.

Pulumi type: `infisical:index/certManagerCertificatePolicy:CertManagerCertificatePolicy`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.CertManagerCertificatePolicy(
  "certManagerCertificatePolicy",
  {},
)
```

## Arguments

| Property            | Type                                                    | Required | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------- | ------------------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `algorithms`        | `CertManagerCertificatePolicyAlgorithms (input)`        | no       | Algorithm constraints for the certificate policy. Omit the block to accept any algorithm; each list restricts its own kind independently and needs at least one value when set.                                                                                                                                                                                                                                                                                                                                                   |
| `basicConstraints`  | `CertManagerCertificatePolicyBasicConstraints (input)`  | no       | Basic constraints policy for the certificate policy, controlling whether issued certificates may act as certificate authorities.                                                                                                                                                                                                                                                                                                                                                                                                  |
| `description`       | `string`                                                | no       | The description of the certificate policy (max 255 characters). Omit the attribute instead of passing an empty string.                                                                                                                                                                                                                                                                                                                                                                                                            |
| `extendedKeyUsages` | `CertManagerCertificatePolicyExtendedKeyUsages (input)` | no       | Extended key usage policies for the certificate policy. When this block is present, requested extended key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all extended key usages. Omit the block for no constraint.                                                                                                                                                                                                                                                 |
| `keyUsages`         | `CertManagerCertificatePolicyKeyUsages (input)`         | no       | Key usage policies for the certificate policy. When this block is present, requested key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all key usages. Omit the block for no constraint.                                                                                                                                                                                                                                                                            |
| `name`              | `string`                                                | no       | The name of the certificate policy. Must be in slug format: lowercase letters and numbers, separated by single hyphens (e.g. 'web-server-policy').                                                                                                                                                                                                                                                                                                                                                                                |
| `sans`              | `CertManagerCertificatePolicySan (input)[]`             | no       | Subject alternative name (SAN) policies for the certificate policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `subjects`          | `CertManagerCertificatePolicySubject (input)[]`         | no       | Subject attribute policies for the certificate policy. Each block constrains a single subject DN attribute (e.g. common_name, organization). Values are matched against the corresponding attribute parsed from the CSR; the '\*' wildcard matches any sequence of characters (including dots).`commonName` matches the CN attribute only.`domainComponent`(DC) is an independent attribute matched separately from common_name: a certificate may carry multiple DC values, and each is matched individually against this block. |
| `validity`          | `CertManagerCertificatePolicyValidity (input)`          | no       | Validity constraints for the certificate policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property            | Type                                                     | Computed | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ------------------- | -------------------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `algorithms`        | `CertManagerCertificatePolicyAlgorithms (output)`        | no       | Algorithm constraints for the certificate policy. Omit the block to accept any algorithm; each list restricts its own kind independently and needs at least one value when set.                                                                                                                                                                                                                                                                                                                                                   |
| `basicConstraints`  | `CertManagerCertificatePolicyBasicConstraints (output)`  | no       | Basic constraints policy for the certificate policy, controlling whether issued certificates may act as certificate authorities.                                                                                                                                                                                                                                                                                                                                                                                                  |
| `description`       | `string`                                                 | no       | The description of the certificate policy (max 255 characters). Omit the attribute instead of passing an empty string.                                                                                                                                                                                                                                                                                                                                                                                                            |
| `extendedKeyUsages` | `CertManagerCertificatePolicyExtendedKeyUsages (output)` | no       | Extended key usage policies for the certificate policy. When this block is present, requested extended key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all extended key usages. Omit the block for no constraint.                                                                                                                                                                                                                                                 |
| `keyUsages`         | `CertManagerCertificatePolicyKeyUsages (output)`         | no       | Key usage policies for the certificate policy. When this block is present, requested key usages must be within the union of allowed and required; setting allowed and required to empty lists denies all key usages. Omit the block for no constraint.                                                                                                                                                                                                                                                                            |
| `name`              | `string`                                                 | no       | The name of the certificate policy. Must be in slug format: lowercase letters and numbers, separated by single hyphens (e.g. 'web-server-policy').                                                                                                                                                                                                                                                                                                                                                                                |
| `sans`              | `CertManagerCertificatePolicySan (output)[]`             | no       | Subject alternative name (SAN) policies for the certificate policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `subjects`          | `CertManagerCertificatePolicySubject (output)[]`         | no       | Subject attribute policies for the certificate policy. Each block constrains a single subject DN attribute (e.g. common_name, organization). Values are matched against the corresponding attribute parsed from the CSR; the '\*' wildcard matches any sequence of characters (including dots).`commonName` matches the CN attribute only.`domainComponent`(DC) is an independent attribute matched separately from common_name: a certificate may carry multiple DC values, and each is matched individually against this block. |
| `validity`          | `CertManagerCertificatePolicyValidity (output)`          | no       | Validity constraints for the certificate policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |

## `CertManagerCertificatePolicyAlgorithms (input)`

Input object `CertManagerCertificatePolicyAlgorithms`. Fields below belong to this object, not to the parent.

| Property        | Type       | Required | Description                                                                                                                                                        |
| --------------- | ---------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `keyAlgorithms` | `string[]` | no       | List of allowed key algorithms (at least one value when set). Supported values: RSA-2048, RSA-3072, RSA-4096, ECDSA-P256, ECDSA-P521, ECDSA-P384                   |
| `signatures`    | `string[]` | no       | List of allowed signature algorithms (at least one value when set). Supported values: SHA256-RSA, SHA512-RSA, SHA384-ECDSA, SHA384-RSA, SHA256-ECDSA, SHA512-ECDSA |

## `CertManagerCertificatePolicyBasicConstraints (input)`

Input object `CertManagerCertificatePolicyBasicConstraints`. Fields below belong to this object, not to the parent.

| Property        | Type     | Required | Description                                                                                                                                                                                                                                                                         |
| --------------- | -------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `isCa`          | `string` | no       | Policy for the CA flag (basic constraints CA:TRUE) on issued certificates. Possible values: allowed, required, denied                                                                                                                                                               |
| `maxPathLength` | `number` | no       | Maximum path length constraint for CA certificates. Use -1 for unlimited, or a non-negative integer to cap how many intermediate CAs may appear below a certificate issued under this policy. Only applies when `isCa` is allowed or required; it is ignored when `isCa` is denied. |

## `CertManagerCertificatePolicyExtendedKeyUsages (input)`

Input object `CertManagerCertificatePolicyExtendedKeyUsages`. Fields below belong to this object, not to the parent.

| Property    | Type       | Required | Description                                                                                                                                  |
| ----------- | ---------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `alloweds`  | `string[]` | no       | List of allowed extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping  |
| `denieds`   | `string[]` | no       | List of denied extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping   |
| `requireds` | `string[]` | no       | List of required extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping |

## `CertManagerCertificatePolicyKeyUsages (input)`

Input object `CertManagerCertificatePolicyKeyUsages`. Fields below belong to this object, not to the parent.

| Property    | Type       | Required | Description                                                                                                                                                                                 |
| ----------- | ---------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `alloweds`  | `string[]` | no       | List of allowed key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only  |
| `denieds`   | `string[]` | no       | List of denied key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only   |
| `requireds` | `string[]` | no       | List of required key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only |

## `CertManagerCertificatePolicySan (input)`

Input object `CertManagerCertificatePolicySan`. Fields below belong to this object, not to the parent.

| Property    | Type       | Required | Description                                                     |
| ----------- | ---------- | -------- | --------------------------------------------------------------- |
| `alloweds`  | `string[]` | no       | List of allowed values for this SAN type                        |
| `denieds`   | `string[]` | no       | List of denied values for this SAN type                         |
| `requireds` | `string[]` | no       | List of required values for this SAN type                       |
| `type`      | `string`   | yes      | The SAN type. Possible values: dns_name, ip_address, email, uri |

## `CertManagerCertificatePolicySubject (input)`

Input object `CertManagerCertificatePolicySubject`. Fields below belong to this object, not to the parent.

| Property    | Type       | Required | Description                                                                                                                             |
| ----------- | ---------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| `alloweds`  | `string[]` | no       | List of allowed values for this subject attribute. Supports the '\*' wildcard.                                                          |
| `denieds`   | `string[]` | no       | List of denied values for this subject attribute. Supports the '\*' wildcard.                                                           |
| `requireds` | `string[]` | no       | List of required values for this subject attribute. Supports the '\*' wildcard.                                                         |
| `type`      | `string`   | yes      | The subject attribute type. Possible values: common_name, organization, organizational_unit, country, state, locality, domain_component |

## `CertManagerCertificatePolicyValidity (input)`

Input object `CertManagerCertificatePolicyValidity`. Fields below belong to this object, not to the parent.

| Property | Type     | Required | Description                                       |
| -------- | -------- | -------- | ------------------------------------------------- |
| `max`    | `string` | no       | Maximum validity period (e.g., '90d', '2y', '6m') |

## `CertManagerCertificatePolicyAlgorithms (output)`

Output object `CertManagerCertificatePolicyAlgorithms`. Fields below belong to this object.

| Property        | Type       | Always present | Description                                                                                                                                                        |
| --------------- | ---------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `keyAlgorithms` | `string[]` | no             | List of allowed key algorithms (at least one value when set). Supported values: RSA-2048, RSA-3072, RSA-4096, ECDSA-P256, ECDSA-P521, ECDSA-P384                   |
| `signatures`    | `string[]` | no             | List of allowed signature algorithms (at least one value when set). Supported values: SHA256-RSA, SHA512-RSA, SHA384-ECDSA, SHA384-RSA, SHA256-ECDSA, SHA512-ECDSA |

## `CertManagerCertificatePolicyBasicConstraints (output)`

Output object `CertManagerCertificatePolicyBasicConstraints`. Fields below belong to this object.

| Property        | Type     | Always present | Description                                                                                                                                                                                                                                                                         |
| --------------- | -------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `isCa`          | `string` | no             | Policy for the CA flag (basic constraints CA:TRUE) on issued certificates. Possible values: allowed, required, denied                                                                                                                                                               |
| `maxPathLength` | `number` | no             | Maximum path length constraint for CA certificates. Use -1 for unlimited, or a non-negative integer to cap how many intermediate CAs may appear below a certificate issued under this policy. Only applies when `isCa` is allowed or required; it is ignored when `isCa` is denied. |

## `CertManagerCertificatePolicyExtendedKeyUsages (output)`

Output object `CertManagerCertificatePolicyExtendedKeyUsages`. Fields below belong to this object.

| Property    | Type       | Always present | Description                                                                                                                                  |
| ----------- | ---------- | -------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `alloweds`  | `string[]` | no             | List of allowed extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping  |
| `denieds`   | `string[]` | no             | List of denied extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping   |
| `requireds` | `string[]` | no             | List of required extended key usages. Possible values: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping |

## `CertManagerCertificatePolicyKeyUsages (output)`

Output object `CertManagerCertificatePolicyKeyUsages`. Fields below belong to this object.

| Property    | Type       | Always present | Description                                                                                                                                                                                 |
| ----------- | ---------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `alloweds`  | `string[]` | no             | List of allowed key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only  |
| `denieds`   | `string[]` | no             | List of denied key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only   |
| `requireds` | `string[]` | no             | List of required key usages. Possible values: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only |

## `CertManagerCertificatePolicySan (output)`

Output object `CertManagerCertificatePolicySan`. Fields below belong to this object.

| Property    | Type       | Always present | Description                                                     |
| ----------- | ---------- | -------------- | --------------------------------------------------------------- |
| `alloweds`  | `string[]` | no             | List of allowed values for this SAN type                        |
| `denieds`   | `string[]` | no             | List of denied values for this SAN type                         |
| `requireds` | `string[]` | no             | List of required values for this SAN type                       |
| `type`      | `string`   | yes            | The SAN type. Possible values: dns_name, ip_address, email, uri |

## `CertManagerCertificatePolicySubject (output)`

Output object `CertManagerCertificatePolicySubject`. Fields below belong to this object.

| Property    | Type       | Always present | Description                                                                                                                             |
| ----------- | ---------- | -------------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| `alloweds`  | `string[]` | no             | List of allowed values for this subject attribute. Supports the '\*' wildcard.                                                          |
| `denieds`   | `string[]` | no             | List of denied values for this subject attribute. Supports the '\*' wildcard.                                                           |
| `requireds` | `string[]` | no             | List of required values for this subject attribute. Supports the '\*' wildcard.                                                         |
| `type`      | `string`   | yes            | The subject attribute type. Possible values: common_name, organization, organizational_unit, country, state, locality, domain_component |

## `CertManagerCertificatePolicyValidity (output)`

Output object `CertManagerCertificatePolicyValidity`. Fields below belong to this object.

| Property | Type     | Always present | Description                                       |
| -------- | -------- | -------------- | ------------------------------------------------- |
| `max`    | `string` | no             | Maximum validity period (e.g., '90d', '2y', '6m') |
