PageSourceSearch

https://ratify.dev/assets/js/929383a2.15dbec81.js

js ratify.dev collected 2026-09-24 19:26:40 UTC 23,359 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[396],{28453(e,i,r){r.d(i,{R:()=>a,x:()=>c});var n=r(96540);const t={},s=n.createContext(t);function a(e){const i=n.useContext(s);return n.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function c(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:a(e.components),n.createElement(s.Provider,{value:i},e.children)}},69439(e,i,r){r.r(i),r.d(i,{assets:()=>l,contentTitle:()=>c,default:()=>h,frontMatter:()=>a,metadata:()=>n,toc:()=>d});const n=JSON.parse('{"id":"reference/custom resources/key-management-providers","title":"Key Management Provider","description":"NOTE: KeyManagementProvider replaces CertificateStore which is now DEPRECATED. See migration guide.","source":"@site/versioned_docs/version-1.4/reference/custom resources/key-management-providers.md","sourceDirName":"reference/custom resources","slug":"/reference/custom resources/key-management-providers","permalink":"/docs/reference/custom resources/key-management-providers","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.4/reference/custom resources/key-management-providers.md","tags":[],"version":"1.4","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"Certificate Store (Deprecated)","permalink":"/docs/reference/custom resources/certificate-stores"},"next":{"title":"policies","permalink":"/docs/reference/custom resources/policies"}}');var t=r(74848),s=r(28453);const a={},c="Key Management Provider",l={},d=[{value:"Table of Contents",id:"table-of-contents",level:2},{value:"Scope",id:"scope",level:2},{value:"Utilization in Verifiers",id:"utilization-in-verifiers",level:2},{value:"Examples",id:"examples",level:3},{value:"Configuration guidelines",id:"configuration-guidelines",level:2},{value:"Inline",id:"inline",level:3},{value:"Template",id:"template",level:4},{value:"Azure Key Vault",id:"azure-key-vault",level:3},{value:"Template",id:"template-1",level:4},{value:"Limitation",id:"limitation",level:2},{value:"Status",id:"status",level:2},{value:"Resource Create/Update",id:"resource-createupdate",level:2},{value:"Migrating from <code>CertificateStore</code> to KMP",id:"migrating-from-certificatestore-to-kmp",level:2},{value:"Inline CertificateStore to Inline KMP",id:"inline-certificatestore-to-inline-kmp",level:3},{value:"Azure Key Vault CertificateStore to Azure Key Vault Key Management Provider",id:"azure-key-vault-certificatestore-to-azure-key-vault-key-management-provider",level:3},{value:"Notation Verifier",id:"notation-verifier",level:3}];function o(e){const i={a:"a",blockquote:"blockquote",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",h4:"h4",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(i.header,{children:(0,t.jsx)(i.h1,{id:"key-management-provider",children:"Key Management Provider"})}),"\n",(0,t.jsxs)(i.blockquote,{children:["\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.strong,{children:"NOTE:"})," ",(0,t.jsx)(i.code,{children:"KeyManagementProvider"})," replaces ",(0,t.jsx)(i.code,{children:"CertificateStore"})," which is now DEPRECATED. See migration ",(0,t.jsx)(i.a,{href:"#migrating-from-certificatestore-to-kmp",children:"guide"}),"."]}),"\n"]}),"\n",(0,t.jsxs)(i.p,{children:["A ",(0,t.jsx)(i.code,{children:"KeyManagementProvider"})," (",(0,t.jsx)(i.code,{children:"KMP"}),") represents key(s) and/or certificate(s) that are consumed by a verifier. ",(0,t.jsx)(i.code,{children:"KMP"})," contains various providers for different use cases. Each provider is responsible for defining custom configuration and providing a set of public keys and/or x.509 certificates. Notation and Cosign verifiers can consume ",(0,t.jsx)(i.code,{children:"KMP"})," resources to use during signature verification. Please refer to respective ",(0,t.jsx)(i.a,{href:"/docs/plugins/verifier/notation",children:"Notation"})," and ",(0,t.jsx)(i.a,{href:"/docs/plugins/verifier/cosign",children:"Cosign"}
1)," verifier documentation on how to consume ",(0,t.jsx)(i.code,{children:"KMP"}),"."]}),"\n",(0,t.jsx)(i.h2,{id:"table-of-contents",children:"Table of Contents"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#key-management-provider",children:"Key Management Provider"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#table-of-contents",children:"Table of Contents"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#scope",children:"Scope"})}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.a,{href:"#utilization-in-verifiers",children:"Utilization in Verifiers"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#examples",children:"Examples"})}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.a,{href:"#configuration-guidelines",children:"Configuration guidelines"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.a,{href:"#inline",children:"Inline"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#template",children:"Template"})}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsx)(i.a,{href:"#azure-key-vault",children:"Azure Key Vault"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#template-1",children:"Template"})}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#limitation",children:"Limitation"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#status",children:"Status"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#resource-createupdate",children:"Resource Create/Update"})}),"\n",(0,t.jsxs)(i.li,{children:[(0,t.jsxs)(i.a,{href:"#migrating-from-certificatestore-to-kmp",children:["Migrating from ",(0,t.jsx)(i.code,{children:"CertificateStore"})," to KMP"]}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#inline-certificatestore-to-inline-kmp",children:"Inline CertificateStore to Inline KMP"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#azure-key-vault-certificatestore-to-azure-key-vault-key-management-provider",children:"Azure Key Vault CertificateStore to Azure Key Vault Key Management Provider"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"#notation-verifier",children:"Notation Verifier"})}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(i.h2,{id:"scope",children:"Scope"}),"\n",(0,t.jsxs)(i.p,{children:["Key Management Provider can be defined as cluster-wide resources(using the kind ",(0,t.jsx)(i.code,{children:"KeyManagementProvider"}),") or namespaced resources(using the kind ",(0,t.jsx)(i.code,{children:"NamespacedKeyManagementProvider"}),")."]}),"\n",(0,t.jsx)(i.h2,{id:"utilization-in-verifiers",children:"Utilization in Verifiers"}),"\n",(0,t.jsxs)(i.p,{children:["The KeyManagementProvider serves primarily as a reference to key/certificate stores in Verifier CRs. Given that the Key Management Provider can exist either cluster-wide or within a namespace, users need to include the appropriate namespace prefix when referencing the KMP in Verifier CRs. To reference a namespaced KMP, the format should be ",(0,t.jsx)(i.code,{children:"namespace/kmp-name"}),". Conversely, to reference a cluster-wide KMP, the format should simply be ",(0,t.jsx)(i.code,{children:"kmp-name"}),"."]}),"\n",(0,t.jsx)(i.p,{children:"In general, there are 2 valid use cases. One is a namespaced verifier references a namespaced KMP within the same namespace or a cluster-wide KMP. The other is a cluster-wide verifier references a cluster-wide KMP."}),"\n",(0,t.jsx)(i.h3,{id:"examples",children:"Examples"}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.strong,{children:(0,t.jsx)(i.em,{children:"Scenario 1"})}),": A namespaced verifier referencing both namespaced KMP and cluster-wide KMP."]}),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-yaml",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: NamespacedVerifier\nmetadata:\n  name: verifier-notation\n  namespace: default\nspec:\n  name: notation\n  artifactTypes: application/vnd.cncf.notary.signature\n  parameters:\n    verificationCertStores:\n      certs:\n        - default/ratify-notation-inline-cert-0\n        - ratify-notation-inline-cert-0\n  # skip irrelevant fields\n"})}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.strong,{children:(0,t.jsx)(i.em,{children:"Scenario 2"})}),": A cluster-wide verifier referencing cluster-wide KMP."]}
1),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-yaml",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Verifier\nmetadata:\n  name: verifier-notation\nspec:\n  name: notation\n  artifactTypes: application/vnd.cncf.notary.signature\n  parameters:\n    verificationCertStores:\n      certs:\n        - ratify-notation-inline-cert-0\n  # skip irrelevant fields\n"})}),"\n",(0,t.jsx)(i.h2,{id:"configuration-guidelines",children:"Configuration guidelines"}),"\n",(0,t.jsx)(i.h3,{id:"inline",children:"Inline"}),"\n",(0,t.jsx)(i.h4,{id:"template",children:"Template"}),"\n",(0,t.jsxs)(i.p,{children:["A provider that can specify a ",(0,t.jsx)(i.strong,{children:"single"})," certificate or key. The content is expected to be defined inline in the resource configuration."]}),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-yml",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: KeyManagementProvider # NamespacedKeyManagementProvider has the same spec.\nmetadata:\n  name: # a unique name\nspec:\n  type: inline\n  parameters:\n    contentType: # REQUIRED: [string] (key, certificate)\n    value: # REQUIRED: [string] value of content\nstatus:\n  error: # error message if the operation failed\n  issuccess: # boolean that indicate if operation was successful\n  lastfetchedtime: # timestamp of last attempted fetch operation\n  properties: # provider specific properties of the fetched certificates/keys. If the current fetch operation fails, this property displays the properties of last successfully cached certificate/key\n"})}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"Name"}),(0,t.jsx)(i.th,{children:"Required"}),(0,t.jsx)(i.th,{children:"Description"}),(0,t.jsx)(i.th,{children:"Default Value"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"contentType"}),(0,t.jsx)(i.td,{children:"yes"}),(0,t.jsx)(i.td,{children:"'key' or 'certificate'. Describes content type"}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"value"}),(0,t.jsx)(i.td,{children:"yes"}),(0,t.jsx)(i.td,{children:"string content"}),(0,t.jsx)(i.td,{children:'""'})]})]})]}),"\n",(0,t.jsx)(i.p,{children:"Samples:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"https://github.com/notaryproject/ratify/blob/dev/config/samples/clustered/kmp/config_v1beta1_keymanagementprovider_inline.yaml",children:"Inline KMP"})}),"\n"]}),"\n",(0,t.jsx)(i.h3,{id:"azure-key-vault",children:"Azure Key Vault"}),"\n",(0,t.jsx)(i.h4,{id:"template-1",children:"Template"}),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-yml",children:'apiVersion: config.ratify.deislabs.io/v1beta1\nkind: KeyManagementProvider\nmetadata:\n  name: # a unique name\nspec:\n  type: azurekeyvault\n  refreshInterval: # OPTIONAL: [string], time duration to refresh the certificates/keys. Disabled by default. Example: 1h, 30m, 1h30m. Valid time units are "ns", "us" (or "\xb5s"), "ms", "s", "m", "h"\n  parameters:\n    vaultURI: # REQUIRED: [string], azure key vault URI\n    tenantID: # REQUIRED: [string], Azure tenant ID\n    clientID: # REQUIRED: [string], client ID of the identity to use to access key vault\n    certificates: # OPTIONAL: [list], certificates in key vault to fetch\n      - name: # REQUIRED: [string], certificate name\n        version: # OPTIONAL [string], version identifier\n    keys: # OPTIONAL: [list], keys in key vault to fetch\n      - name: # REQUIRED: [string], key name\n        version: # OPTIONAL [string], version identifier\n'})}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"Name"}),(0,t.jsx)(i.th,{children:"Required"}),(0,t.jsx)(i.th,{children:"Description"}),(0,t.jsx)(i.th,{children:"Default Value"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"vaultURI"}),(0,t.jsx)(i.td,{children:"yes"}),(0,t.jsx)(i.td,{children:"Azure key vault URI"}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"tenantID"}),(0,t.jsx)(i.td,{children:"yes"}),(0,t.jsx)(i.td,{children:"Azure tenant ID"}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"clientID"}),(0,t.jsx)(i.td,{children:"yes"}),(0,t.jsx)(i.td,{children:"client ID of the identity to use to access key vault"}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"certificates"}),(0,t.jsx)(i.td,{children:"no"}),(0,t.jsx)(i.td,{children:"list of certificates in key vault to fetch"}),(0,t.jsx)(i.td,{children:"[]"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"certificates[*].name"}),(0,t.jsx)(i.td,{children:"yes"}
1),(0,t.jsx)(i.td,{children:"certificate name (as shown in key vault)"}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"certificates[*].version"}),(0,t.jsx)(i.td,{children:"no"}),(0,t.jsx)(i.td,{children:"version identifier (as shown in key vault). If not provided, latest version will be used."}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"keys"}),(0,t.jsx)(i.td,{children:"no"}),(0,t.jsx)(i.td,{children:"list of keys in key vault to fetch"}),(0,t.jsx)(i.td,{children:"[]"})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"keys[*].name"}),(0,t.jsx)(i.td,{children:"yes"}),(0,t.jsx)(i.td,{children:"key name (as shown in key vault)"}),(0,t.jsx)(i.td,{children:'""'})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:"keys[*].version"}),(0,t.jsx)(i.td,{children:"no"}),(0,t.jsx)(i.td,{children:"version identifier (as shown in key vault). If not provided, latest version will be used"}),(0,t.jsx)(i.td,{children:'""'})]})]})]}),"\n",(0,t.jsx)(i.p,{children:"Samples:"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"https://github.com/notaryproject/ratify/blob/dev/config/samples/clustered/kmp/config_v1beta1_keymanagementprovider_akv.yaml",children:"Azure Key Vault KMP"})}),"\n",(0,t.jsx)(i.li,{children:(0,t.jsx)(i.a,{href:"https://github.com/notaryproject/ratify/blob/dev/config/samples/clustered/kmp/config_v1beta1_keymanagementprovider_akv_refresh_enabled.yaml",children:"Azure Key Vault KMP Refresh Enabled"})}),"\n"]}),"\n",(0,t.jsx)(i.h2,{id:"limitation",children:"Limitation"}),"\n",(0,t.jsxs)(i.ul,{children:["\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsx)(i.p,{children:"If a key/certificate is in disabled state, KMP resource creation will FAIL. Users must remove reference to a disabled Key/Certificate or re-enable in Azure Key Vault."}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:["Ratify supports periodic refresh and polling of certificates/keys from Azure Key Vault. The ",(0,t.jsx)(i.code,{children:"refreshInterval"})," field can be set to a time duration to refresh the certificates/keys. When no version of the certificate or key is specified, the latest version will be fetched and the resource will be updated. However, if a version is specified, the resource will be locked to that version and will not be updated."]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:["If the ",(0,t.jsx)(i.code,{children:"refreshInterval"})," is set, verification may fail if the artifact being verified is signed with an older version of the certificate/key even if the older version is still valid/enabled. This is because Ratify only uses the latest stored certificate/key for verification. However, ",(0,t.jsx)(i.a,{href:"https://github.com/ratify-project/ratify/issues/1751",children:"support n-versions of certificates/keys"})," is planned in future releases."]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:["If ",(0,t.jsx)(i.code,{children:"keys"})," are configured, the managed identity with ",(0,t.jsx)(i.code,{children:"clientID"})," specified MUST be assigned the correct permissions to list, view, and download keys in the configured Key Vault."]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:["Azure Key Vault Certificates are built on top of keys and secrets. When a certificate is created, an addressable key and secret are also created with the same name. Ratify requires secret permissions to retrieve the public certificates for the entire certificate chain. Please set private keys to Non-exportable at certificate creation time to avoid security risk. Learn more about non-exportable keys ",(0,t.jsx)(i.a,{href:"https://learn.microsoft.com/en-us/azure/key-vault/certificates/how-to-export-certificate?tabs=azure-cli#exportable-and-non-exportable-keys",children:"here"})]}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsx)(i.p,{children:"Certificate/Key MUST be in PEM format. PKCS12 format with nonexportable private keys can NOT be parsed due to limitation of Golang certificate library."}),"\n"]}),"\n",(0,t.jsxs)(i.li,{children:["\n",(0,t.jsxs)(i.p,{children:["Refer to Azure Key Vault setup guide ratify-on-azure ",(0,t.jsx)(i.a,{href:"https://github.com/notaryproject/ratify/blob/main/docs/quickstarts/ratify-on-azure.md#configure-access-policy-for-akv",children:"quick start"}),"."]}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(i.blockquote,{children:["\n",(0,t.jsxs)(i.p,{children:["Note: If you were unable to configure certificate policy, please consider specifying the public root certificate value inline using an ",(0,t.jsx)(i.a,{href:"#inline",children:"inline key management provider"})," to reduce risk of exposing a private key."]}),"\n"]}),"\n",(0,t.jsx)(i.h2,{id:"status",children:"Status"}),"\n",(0,t.jsx)(i.p,{children:"Get an overview of KMPs status:"}
1),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-bash",children:"kubectl get keymanagementproviders.config.ratify.deislabs.io\n"})}),"\n",(0,t.jsx)(i.p,{children:"Get specific status of each certificate/key fetched in a single KMP"}),"\n",(0,t.jsx)(i.pre,{children:(0,t.jsx)(i.code,{className:"language-bash",children:"kubectl get keymanagementproviders.config.ratify.deislabs.io/<INSERT KMP NAME>\n"})}),"\n",(0,t.jsx)(i.h2,{id:"resource-createupdate",children:"Resource Create/Update"}),"\n",(0,t.jsx)(i.p,{children:"During KMP resource creation, the resource may successfully create even though the provider-specific schema is invalid."}),"\n",(0,t.jsx)(i.p,{children:"For example:"}),"\n",(0,t.jsxs)(i.ol,{children:["\n",(0,t.jsxs)(i.li,{children:["The ",(0,t.jsx)(i.code,{children:"contentType"})," field is missing for the ",(0,t.jsx)(i.code,{children:"inline"})," KMP."]}),"\n",(0,t.jsxs)(i.li,{children:["The ",(0,t.jsx)(i.code,{children:"vaultURI"})," is missing in the Azure Key Vault KMP."]}),"\n"]}),"\n",(0,t.jsxs)(i.p,{children:["Please follow the steps ",(0,t.jsx)(i.a,{href:"#status",children:"here"})," to confirm status of the KMP."]}),"\n",(0,t.jsxs)(i.h2,{id:"migrating-from-certificatestore-to-kmp",children:["Migrating from ",(0,t.jsx)(i.code,{children:"CertificateStore"})," to KMP"]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.code,{children:"CertificateStore"})," resource is deprecated starting in ",(0,t.jsx)(i.code,{children:"v1.2.0"}),". Ratify will continue to support ",(0,t.jsx)(i.code,{children:"CertificateStore"})," functionality until ",(0,t.jsx)(i.code,{children:"v2.0.0"})," at which time it will be removed."]}),"\n",(0,t.jsxs)(i.p,{children:["All existing functionality available in ",(0,t.jsx)(i.code,{children:"CertificateStore"})," is available in ",(0,t.jsx)(i.code,{children:"KeyManagementProvider"}),"."]}),"\n",(0,t.jsx)(i.h3,{id:"inline-certificatestore-to-inline-kmp",children:"Inline CertificateStore to Inline KMP"}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"CertificateStore"}),(0,t.jsx)(i.th,{children:"KeyManagementProvider"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.value"})}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.value"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.contentType"})}),(0,t.jsx)(i.td,{children:"N/A"})]})]})]}),"\n",(0,t.jsxs)(i.p,{children:[(0,t.jsx)(i.code,{children:"contentType"})," is required and must be ",(0,t.jsx)(i.code,{children:"key"})," OR ",(0,t.jsx)(i.code,{children:"certificate"}),". This MUST be added when migrating."]}),"\n",(0,t.jsx)(i.h3,{id:"azure-key-vault-certificatestore-to-azure-key-vault-key-management-provider",children:"Azure Key Vault CertificateStore to Azure Key Vault Key Management Provider"}),"\n",(0,t.jsxs)(i.table,{children:[(0,t.jsx)(i.thead,{children:(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.th,{children:"CertificateStore"}),(0,t.jsx)(i.th,{children:"KeyManagementProvider"})]})}),(0,t.jsxs)(i.tbody,{children:[(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.clientID"})}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.clientId"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.tenantID"})}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.tenantID"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.vaultURI"})}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.vaultURI"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.certificates"})}),(0,t.jsxs)(i.td,{children:[(0,t.jsx)(i.code,{children:".parameters.certificates[]"})," String content is now defined objects"]})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.certificates[*].certificateName"})}
1),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.certificates[*].name"})})]}),(0,t.jsxs)(i.tr,{children:[(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.certificates[*].certificateVersion"})}),(0,t.jsx)(i.td,{children:(0,t.jsx)(i.code,{children:".parameters.certificates[*].version"})})]})]})]}),"\n",(0,t.jsx)(i.h3,{id:"notation-verifier",children:"Notation Verifier"}),"\n",(0,t.jsxs)(i.p,{children:["Notation verifier's ",(0,t.jsx)(i.code,{children:"verificationCertStores"})," array must be updated to reference the ",(0,t.jsx)(i.code,{children:"KeyManagementProvider"})," resource name"]})]})}function h(e={}){const{wrapper:i}={...(0,s.R)(),...e.components};return i?(0,t.jsx)(i,{...e,children:(0,t.jsx)(o,{...e})}):o(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.