1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[2146],{28453(e,t,r){r.d(t,{R:()=>n,x:()=>a});var i=r(96540);const s={},c=i.createContext(s);function n(e){const t=i.useContext(c);return i.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:n(e.components),i.createElement(c.Provider,{value:t},e.children)}},31305(e,t,r){r.r(t),r.d(t,{assets:()=>o,contentTitle:()=>a,default:()=>f,frontMatter:()=>n,metadata:()=>i,toc:()=>d});const i=JSON.parse('{"id":"reference/custom resources/certificate-stores","title":"Certificate Store (Deprecated)","description":"WARNING!: CertificateStore is DEPRECATED in favor of KeyManagementProvider. Please migrate to KeyManagementProvider by following guide here. Support will be removed in v2.0.0","source":"@site/versioned_docs/version-1.4/reference/custom resources/certificate-stores.md","sourceDirName":"reference/custom resources","slug":"/reference/custom resources/certificate-stores","permalink":"/docs/reference/custom resources/certificate-stores","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.4/reference/custom resources/certificate-stores.md","tags":[],"version":"1.4","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"API Upgrade Instructions","permalink":"/docs/reference/custom resources/api-upgrade-instruction"},"next":{"title":"Key Management Provider","permalink":"/docs/reference/custom resources/key-management-providers"}}');var s=r(74848),c=r(28453);const n={},a="Certificate Store (Deprecated)",o={},d=[{value:"AzureKeyVault Certificate Provider",id:"azurekeyvault-certificate-provider",level:2},{value:"Limitation",id:"limitation",level:3},{value:"Inline Certificate Provider",id:"inline-certificate-provider",level:2},{value:"Certificate Specification",id:"certificate-specification",level:2},{value:"CRD Resource Create/Update",id:"crd-resource-createupdate",level:2}];function l(e){const t={a:"a",blockquote:"blockquote",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,c.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.header,{children:(0,s.jsx)(t.h1,{id:"certificate-store-deprecated",children:"Certificate Store (Deprecated)"})}),"\n",(0,s.jsxs)(t.blockquote,{children:["\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"WARNING!:"})," ",(0,s.jsx)(t.code,{children:"CertificateStore"})," is ",(0,s.jsx)(t.strong,{children:"DEPRECATED"})," in favor of ",(0,s.jsx)(t.code,{children:"KeyManagementProvider"}),". Please migrate to ",(0,s.jsx)(t.a,{href:"/docs/reference/custom%20resources/key-management-providers",children:(0,s.jsx)(t.code,{children:"KeyManagementProvider"})})," by following guide ",(0,s.jsx)(t.a,{href:"/docs/reference/custom%20resources/key-management-providers#migrating-from-certificatestore-to-kmp",children:"here"}),". Support will be removed in ",(0,s.jsx)(t.code,{children:"v2.0.0"})]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:["A ",(0,s.jsx)(t.code,{children:"CertificateStore"})," resource defines an array of public certificates to fetch from a provider."]}),"\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.code,{children:"CertificateStore"})," is defined as namespaced resources, which is different from other Custom Resources. A verification request targeting a namespace can only access ",(0,s.jsx)(t.code,{children:"CertificateStore"})," within that namespace. However, a cluster-wide verification request, where the namespace is left empty, can access ",(0,s.jsx)(t.code,{children:"CertificateStore"})," across all namespaces. If you aim to isolate access among namespaces, consider employing ",(0,s.jsx)(t.a,{href:"/docs/reference/custom%20resources/key-management-providers",children:"Key Management Provider"})," by following migration ",(0,s.jsx)(t.a,{href:"/docs/reference/custom%20resources/key-management-providers#migrating-from-certificatestore-to-kmp",children:"guide"}),"."]}),"\n",(0,s.jsxs)(t.p,{children:["View more CRD samples ",(0,s.jsx)(t.a,{href:"https://github.com/ratify-project/ratify/tree/main/config/samples",children:"here"}),". Each provider must specify the ",(0,s.jsx)(t.code,{children:"name"})," of the certificate store."]}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-yml",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: CertificateStore\nmetadata:\n name: \nspec:\n provider: # required, name of the certificate store provider\n parameters: # required, parameters specific to this certificate store provider\nstatus: # supported in version >= config.ratify.deislabs.io/v1beta1\n error: # error message if the operation failed\n issuccess: # boolean that indicate if operation was successful\n lastfetchedtime: # timestamp of last attempted certificate fetch operation\n properties: # provider specific properties of the fetched certificates. If the current certificate fetch operation fails, this property displays the properties of last successfully cached certificate\n"})}),"\n",(0,s.jsx)(t.h2,{id:"azurekeyvault-certificate-provider",children:"AzureKeyVault Certificate Provider"}),"\n",(0,s.jsxs)(t.p,{children:["See notation integration example ",(0,s.jsx)(t.a,{href:"/docs/concepts/verifier#section-6-built-in-verifiers",children:"here"})]}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-yml",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: CertificateStore\nmetadata:\n name: certstore-akv\nspec:\n provider: azurekeyvault\n parameters:\n vaultURI: https://yourke
1yvault.vault.azure.net/\n certificates: |\n array:\n - |\n certificateName: yourCertName\n certificateVersion: yourCertVersion \n tenantID:\n clientID:\nstatus:\n issuccess: true\n lastfetchedtime: # time stamp of last fetch operation\n properties: \n certificates:\n certificate Name: yourCertName\n last Refreshed: # time stamp of last successful cert fetch operation\n version: yourCertVersion \n"})}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Name"}),(0,s.jsx)(t.th,{children:"Required"}),(0,s.jsx)(t.th,{children:"Description"}),(0,s.jsx)(t.th,{children:"Default Value"})]})}),(0,s.jsxs)(t.tbody,{children:[(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"vaultURI"}),(0,s.jsx)(t.td,{children:"yes"}),(0,s.jsx)(t.td,{children:"URI of the azure key vault"}),(0,s.jsx)(t.td,{children:'""'})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"certificateName"}),(0,s.jsx)(t.td,{children:"yes"}),(0,s.jsx)(t.td,{children:"the name of the key vault object"}),(0,s.jsx)(t.td,{children:'""'})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"certificateVersion"}),(0,s.jsx)(t.td,{children:"no"}),(0,s.jsx)(t.td,{children:"provider will fetch latest version if empty"}),(0,s.jsx)(t.td,{children:'""'})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"tenantID"}),(0,s.jsx)(t.td,{children:"yes"}),(0,s.jsx)(t.td,{children:"tenantID of the workload identity that have read access to this key vault"}),(0,s.jsx)(t.td,{children:'""'})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"clientID"}),(0,s.jsx)(t.td,{children:"yes"}),(0,s.jsx)(t.td,{children:"clientID of the workload identity that have read access to this key vault"}),(0,s.jsx)(t.td,{children:'""'})]})]})]}),"\n",(0,s.jsxs)(t.p,{children:["Use command ",(0,s.jsx)(t.code,{children:"kubectl get certificatestores.config.ratify.deislabs.io"})," to see a overview of ",(0,s.jsx)(t.code,{children:"certificatestores"})," status.\nUse command ",(0,s.jsx)(t.code,{children:"kubectl get certificatestores.config.ratify.deislabs.io/certstore-akv"})," to see full details on each certificate."]}),"\n",(0,s.jsx)(t.h3,{id:"limitation",children:"Limitation"}),"\n",(0,s.jsxs)(t.p,{children:["Azure keyvault Certificates are built on top of keys and secrets. When a certificate is created, an addressable key and secret are also created with the same name. Ratify requires secret permissions to retrieve the public certificates for the entire certificate chain, please set private keys to Non-exportable at certificate creation time to avoid security risk. Learn more about non-exportable keys ",(0,s.jsx)(t.a,{href:"https://learn.microsoft.com/en-us/azure/key-vault/certificates/how-to-export-certificate?tabs=azure-cli#exportable-and-non-exportable-keys",children:"here"})]}),"\n",(0,s.jsx)(t.p,{children:"Please also ensure the certificate is in PEM format, PKCS12 format with nonexportable private keys can not be parsed due to limitation of Golang certificate library."}),"\n",(0,s.jsxs)(t.p,{children:["Akv set up guide in ratify-on-azure ",(0,s.jsx)(t.a,{href:"https://github.com/notaryproject/ratify/blob/main/docs/quickstarts/ratify-on-azure.md#configure-access-policy-for-akv",children:"quick start"}),"."]}),"\n",(0,s.jsxs)(t.blockquote,{children:["\n",(0,s.jsxs)(t.p,{children:["Note: If you were unable to configure certificate policy, please consider specifying the public root certificate value inline using the ",(0,s.jsx)(t.a,{href:"/docs/reference/custom%20resources/certificate-stores#inline-certificate-provider",children:"inline certificate provider"})," to reduce risk of exposing private key."]}),"\n"]}),"\n",(0,s.jsx)(t.h2,{id:"inline-certificate-provider",children:"Inline Certificate Provider"}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-yaml",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: CertificateStore\nmetadata:\n name: certstore-inline\nspec:\n provider: inline\n parameters:\n value: |\n -----BEGIN CERTIFICATE-----\n MIIDWDCCAkCgAwIBAgIBUTANBgkqhkiG9w0BAQsFADBaMQswCQYDVQQGEwJVUzEL\n MAkGA1UECBMCV0ExEDAOBgNVBAcTB1NlYXR0bGUxDzANBgNVBAoTBk5vdGFyeTEb\n MBkGA1UEAxMSd2FiYml0LW5ldHdvcmtzLmlvMCAXDTIyMTIwMjA4MDg0NFoYDzIx\n MjIxMjAzMDgwODQ0WjBaMQswCQYDVQQGEwJVUzELMAkGA1UECBMCV0ExEDAOBgNV\n BAcTB1NlYXR0bGUxDzANBgNVBAoTBk5vdGFyeTEbMBkGA1UEAxMSd2FiYml0LW5l\n dHdvcmtzLmlvMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnoskJWB0\n ZsYcfbTvCYQMLqWaB/yN3Jf7Ryxvndrij83fWEQPBQJi8Mk8SpNqm2x9uP3gsQDc\n L/73a0p6/D+hza2jQQVhebe/oB0LJtUoD5LXlJ83UQdZETLMYAzeBNcBR4kMecrY\n CnE6yjHeiEWdAH+U7Mt39zJh+9lGIcbk0aUE5UOp8o3t5RWFDcl9hQ7QOXROwmpO\n thLUIiY/bcPpsg/2nH1nzFjqiBef3sgopFCTgtJ7qF8B83Xy/+hJ5vD29xsbSwuB\n 3iLE7qLxu2NxdIa4oL0Y2QKMh/getjI0xnvwAmPkFiFbzC7LFdDfd6+gA5GpUXxL\n u6UmwucAgiljGQIDAQABoycwJTAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYI\n KwYBBQUHAwMwDQYJKoZIhvcNAQELBQADggEBAFvRW/mGjnnMNFKJc/e3o/+yiJor\n dcrq/1UzyD7eNmOaASXz8rrrFT/6/TBXExPuB2OIf9OgRJFfPGLxmzCwVgaWQbK0\n VfTN4MQzRrSwPmNYsBAAwLxXbarYlMbm4DEmdJGyVikq08T2dZI51GC/YXEwzlnv\n ldN0dBflb/FKkY5rAp0JgpHLGKeStxFvB62noBjWfrm7ShCf9gkn1CjmgvP/sYK0\n pJgA1FHPd6EeB6yRBpLV4EJgQYUJoOpbHz+us62jKj5fAXsX052LPmk9ArmP0uJ1\n CJLNdj+aShCs4paSWOObDmIyXHwCx3MxCvYsFk/Wsnwura6jGC+cNsjzSx4=\n -----END CERTIFICATE-----\n\n"})}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Name"}),(0,s.jsx)(t.th,{children:"Required"}),(0,s.jsx)(t.th,{children:"Description"}),(0,s.jsx)(t.th,{children:"Default Value"})]})}),(0,s.jsx)(t.tbody,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"value"}),(0,s.jsx)(t.td,{children:"yes"}),(0,s.jsx)(t.td,{children:"public certificate content"}),(0,s.jsx)(t.td,{children:'""'})]})})]}),"\n",(0,s.jsx)(t.h2,{id:"certificate-specification",children:"Certificate Specification"}),"\n",(0,s.jsxs)(t.p,{children:["The main use case of certificate store is for notation verifier in Ratify, so users must follow the ",(0,s.jsx)(t.a,{href:"https://github.com/notaryproject/notaryproject/blob/main/specs/trust-store-trust-policy.md#trust-store",children:"TrustStore specification"})," defined by notation."]}),"\n",(0,s.jsx)(t.p,{children:"In brief, users must provide CA certificates or self-signed signing certificates, which means leaf certificates are not allowed to be used. Whatever certificates are provided, Ratify would keep only CA certificates and self-signed certificates. Therefore, if only leaf certificates are provided, Ratify would fail the verification directly since there are no valid certificates."}),"\n",(0,s.jsx)(t.h2,{id:"crd-resource-createupdate",children:"CRD Resource Create/Update"}),"\n",(0,s.jsx)(t.p,{children:"During the CRD creating/updating process, some matters require attention. The CRD operation could be successful even though some invalid values or typos are provided. Examples:"}),"\n",(0,s.jsxs)(t.ol,{children:["\n",(0,s.jsx)(t.li,{children:"Invalid certificate value is provided in inline certificate provider."}),"\n",(0,s.jsx)(t.li,{children:"Invalid vaultUri/certificateName or typos within them are provided in AKV certificate provider."}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"However, those invalid values or typos would cause failures while parsing certificates and signature verification in Ratify.\nSo it's recommended to check the CRD status once the CRD operation is done."})]})}function f(e={}){const{wrapper:t}={...(0,c.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(l,{...e})}):l(e)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.