cat >openssl.conf <<EOF
[req]
distinguished_name = req_distinguished_name
x509_extensions = v3_req
prompt = no
[req_distinguished_name]
CN = $STAX_VAULT_CERT_CN
[v3_req]
basicConstraints = CA:TRUE
EOF
openssl req -x509 -nodes -days 3650 \
-newkey rsa:2048 -keyout $STAX_VAULT_CERT_CN.key \
-out $STAX_VAULT_CERT_CN.crt -config openssl.conf
vault write auth/cert/certs/$STAX_VAULT_CERT_CN \
display_name=aws-stax-$STAX_NAME \
policies=aws-stax-$STAX_NAME \
certificate=@${STAX_VAULT_CERT_CN}.crt
vault auth -method=cert -client-cert=aws_stax_vpc_stax_24302_scytheless.crt -client-key=aws_stax_vpc_stax_24302_scytheless.key
curl --cert certificate.pfx $VAULT_ADDR/v1/auth/cert/login -XPOST -v
--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.
GitHub Issues: https://github.com/hashicorp/vault/issues
IRC: #vault-tool on Freenode
---
You received this message because you are subscribed to the Google Groups "Vault" group.
To unsubscribe from this group and stop receiving emails from it, send an email to vault-tool+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/d9d0ebce-4a3f-483c-b54f-41bf11245a04%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
curl -XPUT https://<vault-server>/v1/auth/cert/login --cert /vault/<client-cert>.crt --key /vault/<client-cert>.key
Error making API request.
URL: PUT https://<vault-server>/v1/auth/cert/login
Code: 400. Errors:
* invalid certificate or no client certificate supplied
--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.
GitHub Issues: https://github.com/hashicorp/vault/issues
IRC: #vault-tool on Freenode
---
You received this message because you are subscribed to the Google Groups "Vault" group.
To unsubscribe from this group and stop receiving emails from it, send an email to vault-tool+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/af26d6ad-c475-4b10-9a3d-cd0db91263ba%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/4eb9bbc8-acdb-4fe0-84f7-b5cf84177396%40googlegroups.com.
{"type":"request","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.1.250"},"error":""}
{"type":"response","error":"","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.1.250"},"response":{"secret":null,"data":{"error":"sha1:d765da7404d3839d712da268cfaa93dad52cece0"},"redirect":""}}
{"type":"request","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.3.71"},"error":""}
{"type":"response","error":"","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.3.71"},"response":{"secret":null,"data":{"error":"sha1:d765da7404d3839d712da268cfaa93dad52cece0"},"redirect":""}}
{"type":"request","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.1.250"},"error":""}
{"type":"response","error":"","auth":{"display_name":"","policies":["aws-stax-vpc-stax-28007-unovercome"],"metadata":{"cert_name":"vpc_stax_28007_unovercome","common_name":"vpc-stax-28007-unovercome"}},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.1.250"},"response":{"auth":{"client_token":"sha1:20b551fe0becfab79e73dcd631dcfcf58d0107bd","display_name":"cert-aws-stax-vpc-stax-28007-unovercome","policies":["aws-stax-vpc-stax-28007-unovercome"],"metadata":{"cert_name":"vpc_stax_28007_unovercome","common_name":"vpc-stax-28007-unovercome"}},"secret":null,"data":null,"redirect":""}}
{"type":"request","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.3.71"},"error":""}
{"type":"response","error":"","auth":{"display_name":"","policies":["aws-stax-vpc-stax-28007-unovercome"],"metadata":{"cert_name":"vpc_stax_28007_unovercome","common_name":"vpc-stax-28007-unovercome"}},"request":{"operation":"write","path":"auth/cert/login","data":null,"remote_address":"10.183.3.71"},"response":{"auth":{"client_token":"sha1:c32eee8449b10a84f9cc5773501c8971d0a57c24","display_name":"cert-aws-stax-vpc-stax-28007-unovercome","policies":["aws-stax-vpc-stax-28007-unovercome"],"metadata":{"cert_name":"vpc_stax_28007_unovercome","common_name":"vpc-stax-28007-unovercome"}},"secret":null,"data":null,"redirect":""}}
{"type":"request","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"read","path":"auth/token/lookup-self","data":null,"remote_address":"10.183.1.250"},"error":""}
{"type":"response","error":"","auth":{"display_name":"","policies":null,"metadata":null},"request":{"operation":"read","path":"auth/token/lookup-self","data":null,"remote_address":"10.183.1.250"},"response":{"secret":null,"data":{"display_name":"sha1:572029b667182883b9735f2c2fa5695c5790ae10","id":"sha1:c32eee8449b10a84f9cc5773501c8971d0a57c24","meta":{"cert_name":"sha1:845db70a72e86a885b3bfb488be9713f452e534d","common_name":"sha1:1fbc59d7c135bf60da30ff64ab22d7a4cf818c3a"},"num_uses":0,"path":"sha1:1beff447d620b21ed7c2a5951e828de08d6197d5","policies":["sha1:7939847343b407411df78e85cca55fa880da3988"]},"redirect":""}}
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/15113e58-def3-4fe9-b216-cf66905d9980%40googlegroups.com.
vault auth -method=cert -client-cert=/root/vault/vpc-stax-28007-unovercome.crt -client-key=/root/vault/vpc-stax-28007-unovercome.key
vault auth -method=cert -client-cert=/root/vault/vpc-stax-28007-unovercome.crt -client-key=/root/vault/vpc-stax-28007-unovercome.key -tls-skip-verify
curl -XPUT https://<vault-url>/v1/auth/cert/login --cert /root/vault/vpc-stax-28007-unovercome.crt --key /root/vault/vpc-stax-28007-unovercome.key
Brian,
...
--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.
GitHub Issues: https://github.com/hashicorp/vault/issues
IRC: #vault-tool on Freenode
---
You received this message because you are subscribed to the Google Groups "Vault" group.
To unsubscribe from this group and stop receiving emails from it, send an email to vault-tool+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/91693d49-df88-4b44-94ca-f768ac8b7ab3%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/vault-tool/cdb3e096-1810-4f3e-8364-0d535ec79d67%40googlegroups.com.