-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Description
When creating an intermediate CA using AWS KMS keys, I would like to be able to have the root and intermediate keys stored in different regions.
We would like to deploy a CAs to multiple regions, using the same root certificate, but with one intermediate per region. I am aware that AWS supports multi-region keys, which is almost certainly how I will accomplish our goals for now, but it would be very useful to be able to specify a different region for --ca-key
and --key
.
For example, we might store a root key in the us-west-1 region and want to create an intermediate in us-east-2:
step certificate create --profile intermediate-ca \
--kms 'awskms:region=us-east-2' \
--ca root_ca.crt \
--ca-key 'awskms:key-id=78980acd-a42d-4d84-97ba-1e50d3082214' \
--key 'awskms:key-id=9432458d-1e67-4a74-9a23-8f94708b45fe;region=us-west-1' \
"Smallstep Intermediate CA" intermediate_ca.crt
Metadata
Metadata
Assignees
Labels
No labels