Skip to content

Add IncludeChain store property for AWSSMPEM, Documentation updates - #9

Merged
indrora merged 10 commits into
release-1.2from
pem-include-chain
Oct 6, 2026
Merged

indrora merged 10 commits into
release-1.2from
pem-include-chain

Conversation

@joevanwanzeeleKF

Copy link
Copy Markdown
Collaborator
  • Added "IncludeChain" property, that conditionally depends on "SeparatePrivateKey" to indicate that the full chain should be included in the cert secret.

  • Updated documentation to include full list of required permissions. Cleaned up formatting.

joevanwanzeeleKF and others added 10 commits September 24, 2026 12:58
Adds an optional IncludeChain store-type property (default false) that
writes the issuer chain into the single concatenated PEM secret (leaf,
then chain leaf-first, then private key). Ignored when SeparatePrivateKey
is enabled, since the JSON format already includes the chain. A missing
property reads as false, so existing stores are unchanged after upgrade.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Inventory calls BatchGetSecretValue and management operations call
DescribeSecret; both fail without these IAM actions but they were not
listed in the documentation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adds UntagResource, ReplicateSecretToRegions, and
RemoveRegionsFromReplication (called when using tags or replica regions)
and fixes the action names to the secretsmanager:<Action> form so they
can be pasted directly into an IAM policy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
UpdateSecretTagsAsync computed the tag keys that overlap with the new
tags but then untagged every existing tag on the secret whenever any
key overlapped, wiping tags not managed by Keyfactor. Only the
overlapping keys are now removed before re-tagging; other tags are
kept. Also adds the .NET 10 target to the changelog.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
When an AWSSMPEM secret failed to parse during inventory, the full
secret value (including the unencrypted private key) was logged at the
Warning level. The warning now contains only the secret name and the
parse error; the malformed warning message is also fixed.

The raw store properties trace now redacts Secret-type fields (OAuth
client ID/secret, IAM user access key/secret).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@indrora
indrora merged commit 0745b76 into release-1.2 Oct 6, 2026
indrora added a commit that referenced this pull request Oct 6, 2026
* Add IncludeChain store property for AWSSMPEM, Documentation updates (#9)

* Add IncludeChain store property for AWSSMPEM

Adds an optional IncludeChain store-type property (default false) that
writes the issuer chain into the single concatenated PEM secret (leaf,
then chain leaf-first, then private key). Ignored when SeparatePrivateKey
is enabled, since the JSON format already includes the chain. A missing
property reads as false, so existing stores are unchanged after upgrade.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: add BatchGetSecretValue and DescribeSecret to required permissions

Inventory calls BatchGetSecretValue and management operations call
DescribeSecret; both fail without these IAM actions but they were not
listed in the documentation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: complete and correct the IAM permissions list

Adds UntagResource, ReplicateSecretToRegions, and
RemoveRegionsFromReplication (called when using tags or replica regions)
and fixes the action names to the secretsmanager:<Action> form so they
can be pasted directly into an IAM policy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Add net10.0 target framework

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Only untag overlapping keys when updating secret tags

UpdateSecretTagsAsync computed the tag keys that overlap with the new
tags but then untagged every existing tag on the secret whenever any
key overlapped, wiping tags not managed by Keyfactor. Only the
overlapping keys are now removed before re-tagging; other tags are
kept. Also adds the .NET 10 target to the changelog.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Stop logging secret contents and credentials

When an AWSSMPEM secret failed to parse during inventory, the full
secret value (including the unencrypted private key) was logged at the
Warning level. The warning now contains only the secret name and the
parse error; the malformed warning message is also fixed.

The raw store properties trace now redacts Secret-type fields (OAuth
client ID/secret, IAM user access key/secret).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Update generated docs

* Update keyfactor-release-workflow.yml

update to v5

* Update keyfactor-release-workflow.yml

* docs: auto-generate README and documentation [skip ci]

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* Update integration-manifest.json (#10)

* docs: auto-generate README and documentation [skip ci]

---------

Co-authored-by: Joe VanWanzeele <76071503+joevanwanzeeleKF@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants