Skip to content

Use --kms for revocation using X5C provisioner聽#1713

Description

@WhatANiceChick

Hello!

  • Vote on this issue by adding a 馃憤 reaction
  • If you want to implement this feature, comment to let us know (we'll work with you on design, scheduling, etc.)

Issue details

Using a X5C provisioner, a user can be authenticated with a Yubikey using --kms. However, this option is not available for revocation.

Why is this needed?

Certificates created using X5C provisioner are often long time certificate (>= 1 year). To me, a user who authenticates with a smartcard for signature should be able to revoke the same way :

$ step ca revoke --kms "yubikey:?pin-prompt" --x5c-cert "yubikey:slot-is=9a" --x5c-key "yubikey:slot-id=9a" <serial>

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementneeds triageWaiting for discussion / prioritization by team

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions