Azure-cli: KeyVault certificate policy format

Created on 17 May 2019  Â·  7Comments  Â·  Source: Azure/azure-cli

What does the json look like? How difficult was it to provide a json for policy on this page? I am trying to create a cert in vault. But it only creates SELF SIGNED. I need to create a key and csr for the non-partnered ca which i am just not able to find. Pls help


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Documentation KeyVault customer-reported

All 7 comments

+1. There is no help regarding JSON policy definition. No links to external page where this is explained. Currently trying to figure out how to create a certificate that is not signed by a known issuer.

Yes exactly, facing the same issue. Infact I contacted the Microsoft azure support team and they are yet to get back to me even after 4 days. Also, in powershell we have apis but same apis are not there in azure CLI. For ex : I can login yo portal and download certificate in pfx format but how do I do it using CLI? No clue. No examples given.

@adi658 Please check if this one helps? https://github.com/Azure/azure-cli/issues/7489

Awesome... that helped.. So we use download secret instead of download certificate. Wierd :(

You may use az keyvault certificate get-default-policy --scaffold to get a template to work with. This is a Python representation of Create Certificate REST API's body: https://docs.microsoft.com/en-us/rest/api/keyvault/createcertificate/createcertificate#certificatepolicy

As @jiasli said, az keyvault certificate get-default-policy --scaffold will give you a rough frame to work with. Closing this issue due to long time inactivity.

Was this page helpful?
0 / 5 - 0 ratings