vault
Last updated
Was this helpful?
Last updated
Was this helpful?
[!NOTE|label:references]
macos
ubunut/debian
centos/rhel
list role type
list roles
read role
get token
list all path
list keys
get contents
[!NOTE|label:references:]
pre-setup
list
setup
[!NOTE|label:references:]
Service tokens
s.<random>
hvs.<random>
Batch tokens
b.<random>
hvb.<random>
Recovery tokens
r.<random>
hvr.<random>
[!TIP]
initial root token with no expiration
generate root token with share holders ( with unseal key )
[!NOTE|label:references:]
unseal key is necessary to generate root token
example:
generate an otp code for the final token
start a root token generation:
enter an unseal key to progress root token generation:
check status
seal/unseal
[!NOTE|label:references:]
mount ssh secret engine
configure vault with a ca
add CA to all servers
create role
create ssh-key paire
sign the public key
saved the signed keys
mount ssh security
configure CA
extend host key certificate ttls
create role
sign ssh public key
signed certificate as HostCertificate
retrieve the host signing ca public key
add into ~/.ssh/authorized_keys
set verbose log level
check in /var/log/auth.log
[!NOTE|label:references:]
[!NOTE|label:references:]
and more
result
[!TIP|label:references]
the API key for root tokens