mrcharles 01197dd761
ci / audit (push) Failing after 39s
[#385] SSH CA live on fleet step-ca: user cert issuance + e2e ssh auth PROVEN
ED25519 user/host CA keys generated; enableSSHCA on JWK provisioner;
24h root principal cert issued and used to ssh into sectestbed 5104
(passwordless, no static key). Host onboarding = 1 file + reload.
Rollout role queued in KNELIAC. Public CA key committed (private keys
never leave tsys-ca).
https://projects.knownelement.com/issues/385
2026-09-05 17:08:16 -05:00

ca

Docs live on Discourse — this repo is the executable source of truth. Topic: https://community.turnsys.com/t/327 Redmine: https://projects.knownelement.com/issues/697 · Split from KNEL/PFVCluster@041d311 per #769

Fleet CA on tsys-ca: init/issue/selftest, fleet TLS rollout, HTTP artifact mirror (pinned wazuh-agent debs + SHA256SUMS). Roadmap: ACME endpoint, k8s CA integration, SSH certificates. [#697]

Layout

  • scripts/ — rule engine + hooks (see bash scripts/check-rules.sh --fast)
  • (imported content at repo root, mirroring its PFVCluster path layout)

Provenance

Code imported from KNEL/PFVCluster (041d311); full git history retained in PFVCluster. Enforcement layer copied per ADOPTING.md. IaC consumers: KNEL/KNELIAC references this repo.

S
Description
Fleet CA: tsys-ca issuance, fleet TLS, artifact mirror; ACME + SSH-cert roadmap [#697]
Readme AGPL-3.0
27 MiB
Languages
Shell 96.5%
Makefile 3.5%