Hello!
- Vote on this issue by adding a 馃憤 reaction
- If you want to implement this feature, comment to let us know (we'll work with you on design, scheduling, etc.)
Issue details
Using a X5C provisioner, a user can be authenticated with a Yubikey using --kms. However, this option is not available for revocation.
Why is this needed?
Certificates created using X5C provisioner are often long time certificate (>= 1 year). To me, a user who authenticates with a smartcard for signature should be able to revoke the same way :
$ step ca revoke --kms "yubikey:?pin-prompt" --x5c-cert "yubikey:slot-is=9a" --x5c-key "yubikey:slot-id=9a" <serial>
Hello!
Issue details
Using a X5C provisioner, a user can be authenticated with a Yubikey using --kms. However, this option is not available for revocation.
Why is this needed?
Certificates created using X5C provisioner are often long time certificate (>= 1 year). To me, a user who authenticates with a smartcard for signature should be able to revoke the same way :