New-SMIssuer
SYNOPSIS
Creates a Secrets Manager issuer
SYNTAX
AWS (Default)
New-SMIssuer [-access_key_id] <String> [-secret_access_key] <SecureString> [-id] <String> [-InformationVariable <String>] [-WarningVariable <String>] [-ErrorVariable <String>] [-PipelineVariable <String>] [-OutBuffer <Int32>] [-OutVariable <String>] [-Debug] [-Verbose] [-max_ttl <Int32>] [-InformationAction <ActionPreference>] [-WarningAction <ActionPreference>] [-ErrorAction <ActionPreference>] [-WhatIf] [-Confirm] [<CommonParameters>]
GCP
New-SMIssuer [-service_account_key_secret_ref] <String> [-id] <String> [-InformationVariable <String>] [-WarningVariable <String>] [-ErrorVariable <String>] [-PipelineVariable <String>] [-OutBuffer <Int32>] [-OutVariable <String>] [-InformationAction <ActionPreference>] [-Verbose] [-access_token_permitted_scope <String[]>] [-max_ttl <Int32>] [-WarningAction <ActionPreference>] [-ErrorAction <ActionPreference>] [-Debug] [-WhatIf] [-Confirm] [<CommonParameters>]
VenafiSaaS
New-SMIssuer [-password_secret_ref] <String> [-default_zone] <String> [-allowed_zones] <String[]> [-user_id_secret_ref] <String> [-id] <String> [-service_account_token_url] <String> [-InformationVariable <String>] [-WarningVariable <String>] [-ErrorVariable <String>] [-PipelineVariable <String>] [-OutBuffer <Int32>] [-OutVariable <String>] [-Debug] [-Verbose] [-max_ttl <Int32>] [-InformationAction <ActionPreference>] [-WarningAction <ActionPreference>] [-ErrorAction <ActionPreference>] [-WhatIf] [-Confirm] [<CommonParameters>]
DESCRIPTION
Creates a new issuer used to create dynamic secrets or certificates. The issuer type determines which parameter set applies: AWS (access key credentials), GCP (a reference to a stored service account key), or PKI_VENAFI_SAAS (Certificate Manager).
EXAMPLES
Example 1
New-SMIssuer
Creates a Secrets Manager issuer
PARAMETERS
-id
The role’s full ID (absolute path).
Type: String
Parameter Sets: (All)
Aliases: issuerName
Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-max_ttl
The maximum time-to-live, in seconds, of dynamic secrets created with this issuer.
Type: Int32
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False
-access_key_id
AWS account access key.
Type: String
Parameter Sets: AWS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-secret_access_key
AWS account secret key.
Type: SecureString
Parameter Sets: AWS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-service_account_key_secret_ref
The Secrets Manager secret ID (full pathname) of the stored GCP service account key.
Type: String
Parameter Sets: GCP
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-access_token_permitted_scope
The scopes that the GCP issuer is permitted to access.
Type: String[]
Parameter Sets: GCP
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-service_account_token_url
Certificate Manager tenant’s token URL.
Type: String
Parameter Sets: VenafiSaaS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-user_id_secret_ref
The Secrets Manager secret ID for the Idira Identity username.
Type: String
Parameter Sets: VenafiSaaS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-password_secret_ref
The Secrets Manager secret ID for the Idira Identity password.
Type: String
Parameter Sets: VenafiSaaS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-default_zone
Certificate Manager’s default zone, used to issue certificates if not otherwise specified.
Type: String
Parameter Sets: VenafiSaaS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-allowed_zones
The zones that workloads can use for certificate requests.
Type: String[]
Parameter Sets: VenafiSaaS
Aliases:
Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-WhatIf
Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
-Confirm
Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.