You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| Location | Location |**global** is the default but could be another region based on the project. | String | global | ✅ Checked |
123
+
| Location | Location |The GCP region used for this Certificate Manager instance. **global** is the default but could be another region based on the project. | String | global | ✅ Checked |
124
124
| ServiceAccountKey | Service Account Key File Path | The file name of the Google Cloud Service Account Key File installed in the same folder as the orchestrator extension. Empty if the orchestrator server resides in GCP and you are not using a service account key. | String || 🔲 Unchecked |
125
125
126
126
The Custom Fields tab should look like this:
@@ -165,12 +165,6 @@ To use the Google Cloud Provider Certificate Manager Universal Orchestrator exte
165
165
Refer to [Starting/Restarting the Universal Orchestrator service](https://software.keyfactor.com/Core-OnPrem/Current/Content/InstallingAgents/NetCoreOrchestrator/StarttheService.htm).
166
166
167
167
168
-
6. **(optional) PAM Integration**
169
-
170
-
The Google Cloud Provider Certificate Manager Universal Orchestrator extension is compatible with all supported Keyfactor PAM extensions to resolve PAM-eligible secrets. PAM extensions running on Universal Orchestrators enable secure retrieval of secrets from a connected PAM provider.
171
-
172
-
To configure a PAM provider, [reference the Keyfactor Integration Catalog](https://keyfactor.github.io/integrations-catalog/content/pam) to select an extension, and follow the associated instructions to install it on the Universal Orchestrator (remote).
173
-
174
168
175
169
> The above installation steps can be supplimented by the [official Command documentation](https://software.keyfactor.com/Core-OnPrem/Current/Content/InstallingAgents/NetCoreOrchestrator/CustomExtensions.htm?Highlight=extensions).
176
170
@@ -198,26 +192,12 @@ To use the Google Cloud Provider Certificate Manager Universal Orchestrator exte
198
192
| Client Machine | GCP Project ID for your account. |
199
193
| Store Path | This is not used and should be defaulted to n/a per the certificate store type set up. |
200
194
| Orchestrator | Select an approved orchestrator capable of managing `GcpCertMgr` certificates. Specifically, one with the `GcpCertMgr` capability. |
201
-
| Location | **global** is the default but could be another region based on the project. |
195
+
| Location | The GCP region used for this Certificate Manager instance. **global** is the default but could be another region based on the project. |
202
196
| ServiceAccountKey | The file name of the Google Cloud Service Account Key File installed in the same folder as the orchestrator extension. Empty if the orchestrator server resides in GCP and you are not using a service account key. |
203
197
204
198
205
199
206
200
207
-
<details><summary>Attributes eligible for retrieval by a PAM Provider on the Universal Orchestrator</summary>
208
-
209
-
If a PAM provider was installed _on the Universal Orchestrator_ in the [Installation](#Installation) section, the following parameters can be configured for retrieval _on the Universal Orchestrator_.
210
-
| Attribute | Description |
211
-
| --------- | ----------- |
212
-
| Location | **global** is the default but could be another region based on the project. |
213
-
214
-
215
-
Please refer to the **Universal Orchestrator (remote)** usage section ([PAM providers on the Keyfactor Integration Catalog](https://keyfactor.github.io/integrations-catalog/content/pam)) for your selected PAM provider for instructions on how to load attributes orchestrator-side.
216
-
217
-
> Any secret can be rendered by a PAM provider _installed on the Keyfactor Command server_. The above parameters are specific to attributes that can be fetched by an installed PAM provider running on the Universal Orchestrator server itself.
218
-
</details>
219
-
220
-
221
201
</details>
222
202
223
203
* **Using kfutil**
@@ -239,24 +219,12 @@ To use the Google Cloud Provider Certificate Manager Universal Orchestrator exte
239
219
| Client Machine | GCP Project ID for your account. |
240
220
| Store Path | This is not used and should be defaulted to n/a per the certificate store type set up. |
241
221
| Orchestrator | Select an approved orchestrator capable of managing `GcpCertMgr` certificates. Specifically, one with the `GcpCertMgr` capability. |
242
-
| Location | **global** is the default but could be another region based on the project. |
222
+
| Location | The GCP region used for this Certificate Manager instance. **global** is the default but could be another region based on the project. |
243
223
| ServiceAccountKey | The file name of the Google Cloud Service Account Key File installed in the same folder as the orchestrator extension. Empty if the orchestrator server resides in GCP and you are not using a service account key. |
244
224
245
225
246
226
247
227
248
-
<details><summary>Attributes eligible for retrieval by a PAM Provider on the Universal Orchestrator</summary>
249
-
250
-
If a PAM provider was installed _on the Universal Orchestrator_ in the [Installation](#Installation) section, the following parameters can be configured for retrieval _on the Universal Orchestrator_.
251
-
| Attribute | Description |
252
-
| --------- | ----------- |
253
-
| Location | **global** is the default but could be another region based on the project. |
254
-
255
-
256
-
> Any secret can be rendered by a PAM provider _installed on the Keyfactor Command server_. The above parameters are specific to attributes that can be fetched by an installed PAM provider running on the Universal Orchestrator server itself.
257
-
</details>
258
-
259
-
260
228
3. **Import the CSV file to create the certificate stores**
0 commit comments