-
AFAIU, Teleport issues short-lived certificates from its own internal CA, which is self-signed. We would like to integrate this CA into our existing PKI. Is it possible to sign TeleportUserCA with our SubCorpCa, like in the diagram below?
I've found the docs to regenerate the CA, but not where it is stored. |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
This is not currently a supported option. |
Beta Was this translation helpful? Give feedback.
-
@uedvt359 If you want to proceed with an unsupported setup, you could try export the user-ca with Reimport the state (https://goteleport.com/docs/management/operations/backup-restore/#example-of-backing-up-and-restoring-a-cluster) and Teleport will try to use the new CA. I believe the Common Name of the CA that teleport uses has to match the |
Beta Was this translation helpful? Give feedback.
This is not currently a supported option.