Documentation ¶
Index ¶
- func CfnConnector_CFN_RESOURCE_TYPE_NAME() *string
- func CfnConnector_IsCfnElement(x interface{}) *bool
- func CfnConnector_IsCfnResource(construct constructs.IConstruct) *bool
- func CfnConnector_IsConstruct(x interface{}) *bool
- func CfnDirectoryRegistration_CFN_RESOURCE_TYPE_NAME() *string
- func CfnDirectoryRegistration_IsCfnElement(x interface{}) *bool
- func CfnDirectoryRegistration_IsCfnResource(construct constructs.IConstruct) *bool
- func CfnDirectoryRegistration_IsConstruct(x interface{}) *bool
- func CfnServicePrincipalName_CFN_RESOURCE_TYPE_NAME() *string
- func CfnServicePrincipalName_IsCfnElement(x interface{}) *bool
- func CfnServicePrincipalName_IsCfnResource(construct constructs.IConstruct) *bool
- func CfnServicePrincipalName_IsConstruct(x interface{}) *bool
- func CfnTemplateGroupAccessControlEntry_CFN_RESOURCE_TYPE_NAME() *string
- func CfnTemplateGroupAccessControlEntry_IsCfnElement(x interface{}) *bool
- func CfnTemplateGroupAccessControlEntry_IsCfnResource(construct constructs.IConstruct) *bool
- func CfnTemplateGroupAccessControlEntry_IsConstruct(x interface{}) *bool
- func CfnTemplate_CFN_RESOURCE_TYPE_NAME() *string
- func CfnTemplate_IsCfnElement(x interface{}) *bool
- func CfnTemplate_IsCfnResource(construct constructs.IConstruct) *bool
- func CfnTemplate_IsConstruct(x interface{}) *bool
- func NewCfnConnector_Override(c CfnConnector, scope constructs.Construct, id *string, ...)
- func NewCfnDirectoryRegistration_Override(c CfnDirectoryRegistration, scope constructs.Construct, id *string, ...)
- func NewCfnServicePrincipalName_Override(c CfnServicePrincipalName, scope constructs.Construct, id *string, ...)
- func NewCfnTemplateGroupAccessControlEntry_Override(c CfnTemplateGroupAccessControlEntry, scope constructs.Construct, id *string, ...)
- func NewCfnTemplate_Override(c CfnTemplate, scope constructs.Construct, id *string, props *CfnTemplateProps)
- type CfnConnector
- type CfnConnectorProps
- type CfnConnector_VpcInformationProperty
- type CfnDirectoryRegistration
- type CfnDirectoryRegistrationProps
- type CfnServicePrincipalName
- type CfnServicePrincipalNameProps
- type CfnTemplate
- type CfnTemplateGroupAccessControlEntry
- type CfnTemplateGroupAccessControlEntryProps
- type CfnTemplateGroupAccessControlEntry_AccessRightsProperty
- type CfnTemplateProps
- type CfnTemplate_ApplicationPoliciesProperty
- type CfnTemplate_ApplicationPolicyProperty
- type CfnTemplate_CertificateValidityProperty
- type CfnTemplate_EnrollmentFlagsV2Property
- type CfnTemplate_EnrollmentFlagsV3Property
- type CfnTemplate_EnrollmentFlagsV4Property
- type CfnTemplate_ExtensionsV2Property
- type CfnTemplate_ExtensionsV3Property
- type CfnTemplate_ExtensionsV4Property
- type CfnTemplate_GeneralFlagsV2Property
- type CfnTemplate_GeneralFlagsV3Property
- type CfnTemplate_GeneralFlagsV4Property
- type CfnTemplate_KeyUsageFlagsProperty
- type CfnTemplate_KeyUsageProperty
- type CfnTemplate_KeyUsagePropertyFlagsProperty
- type CfnTemplate_KeyUsagePropertyProperty
- type CfnTemplate_PrivateKeyAttributesV2Property
- type CfnTemplate_PrivateKeyAttributesV3Property
- type CfnTemplate_PrivateKeyAttributesV4Property
- type CfnTemplate_PrivateKeyFlagsV2Property
- type CfnTemplate_PrivateKeyFlagsV3Property
- type CfnTemplate_PrivateKeyFlagsV4Property
- type CfnTemplate_SubjectNameFlagsV2Property
- type CfnTemplate_SubjectNameFlagsV3Property
- type CfnTemplate_SubjectNameFlagsV4Property
- type CfnTemplate_TemplateDefinitionProperty
- type CfnTemplate_TemplateV2Property
- type CfnTemplate_TemplateV3Property
- type CfnTemplate_TemplateV4Property
- type CfnTemplate_ValidityPeriodProperty
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CfnConnector_CFN_RESOURCE_TYPE_NAME ¶
func CfnConnector_CFN_RESOURCE_TYPE_NAME() *string
func CfnConnector_IsCfnElement ¶
func CfnConnector_IsCfnElement(x interface{}) *bool
Returns `true` if a construct is a stack element (i.e. part of the synthesized cloudformation template).
Uses duck-typing instead of `instanceof` to allow stack elements from different versions of this library to be included in the same stack.
Returns: The construct as a stack element or undefined if it is not a stack element.
func CfnConnector_IsCfnResource ¶
func CfnConnector_IsCfnResource(construct constructs.IConstruct) *bool
Check whether the given construct is a CfnResource.
func CfnConnector_IsConstruct ¶
func CfnConnector_IsConstruct(x interface{}) *bool
Checks if `x` is a construct.
Use this method instead of `instanceof` to properly detect `Construct` instances, even when the construct library is symlinked.
Explanation: in JavaScript, multiple copies of the `constructs` library on disk are seen as independent, completely different libraries. As a consequence, the class `Construct` in each copy of the `constructs` library is seen as a different class, and an instance of one class will not test as `instanceof` the other class. `npm install` will not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of the `constructs` library can be accidentally installed, and `instanceof` will behave unpredictably. It is safest to avoid using `instanceof`, and using this type-testing method instead.
Returns: true if `x` is an object created from a class which extends `Construct`.
func CfnDirectoryRegistration_CFN_RESOURCE_TYPE_NAME ¶
func CfnDirectoryRegistration_CFN_RESOURCE_TYPE_NAME() *string
func CfnDirectoryRegistration_IsCfnElement ¶
func CfnDirectoryRegistration_IsCfnElement(x interface{}) *bool
Returns `true` if a construct is a stack element (i.e. part of the synthesized cloudformation template).
Uses duck-typing instead of `instanceof` to allow stack elements from different versions of this library to be included in the same stack.
Returns: The construct as a stack element or undefined if it is not a stack element.
func CfnDirectoryRegistration_IsCfnResource ¶
func CfnDirectoryRegistration_IsCfnResource(construct constructs.IConstruct) *bool
Check whether the given construct is a CfnResource.
func CfnDirectoryRegistration_IsConstruct ¶
func CfnDirectoryRegistration_IsConstruct(x interface{}) *bool
Checks if `x` is a construct.
Use this method instead of `instanceof` to properly detect `Construct` instances, even when the construct library is symlinked.
Explanation: in JavaScript, multiple copies of the `constructs` library on disk are seen as independent, completely different libraries. As a consequence, the class `Construct` in each copy of the `constructs` library is seen as a different class, and an instance of one class will not test as `instanceof` the other class. `npm install` will not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of the `constructs` library can be accidentally installed, and `instanceof` will behave unpredictably. It is safest to avoid using `instanceof`, and using this type-testing method instead.
Returns: true if `x` is an object created from a class which extends `Construct`.
func CfnServicePrincipalName_CFN_RESOURCE_TYPE_NAME ¶
func CfnServicePrincipalName_CFN_RESOURCE_TYPE_NAME() *string
func CfnServicePrincipalName_IsCfnElement ¶
func CfnServicePrincipalName_IsCfnElement(x interface{}) *bool
Returns `true` if a construct is a stack element (i.e. part of the synthesized cloudformation template).
Uses duck-typing instead of `instanceof` to allow stack elements from different versions of this library to be included in the same stack.
Returns: The construct as a stack element or undefined if it is not a stack element.
func CfnServicePrincipalName_IsCfnResource ¶
func CfnServicePrincipalName_IsCfnResource(construct constructs.IConstruct) *bool
Check whether the given construct is a CfnResource.
func CfnServicePrincipalName_IsConstruct ¶
func CfnServicePrincipalName_IsConstruct(x interface{}) *bool
Checks if `x` is a construct.
Use this method instead of `instanceof` to properly detect `Construct` instances, even when the construct library is symlinked.
Explanation: in JavaScript, multiple copies of the `constructs` library on disk are seen as independent, completely different libraries. As a consequence, the class `Construct` in each copy of the `constructs` library is seen as a different class, and an instance of one class will not test as `instanceof` the other class. `npm install` will not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of the `constructs` library can be accidentally installed, and `instanceof` will behave unpredictably. It is safest to avoid using `instanceof`, and using this type-testing method instead.
Returns: true if `x` is an object created from a class which extends `Construct`.
func CfnTemplateGroupAccessControlEntry_CFN_RESOURCE_TYPE_NAME ¶
func CfnTemplateGroupAccessControlEntry_CFN_RESOURCE_TYPE_NAME() *string
func CfnTemplateGroupAccessControlEntry_IsCfnElement ¶
func CfnTemplateGroupAccessControlEntry_IsCfnElement(x interface{}) *bool
Returns `true` if a construct is a stack element (i.e. part of the synthesized cloudformation template).
Uses duck-typing instead of `instanceof` to allow stack elements from different versions of this library to be included in the same stack.
Returns: The construct as a stack element or undefined if it is not a stack element.
func CfnTemplateGroupAccessControlEntry_IsCfnResource ¶
func CfnTemplateGroupAccessControlEntry_IsCfnResource(construct constructs.IConstruct) *bool
Check whether the given construct is a CfnResource.
func CfnTemplateGroupAccessControlEntry_IsConstruct ¶
func CfnTemplateGroupAccessControlEntry_IsConstruct(x interface{}) *bool
Checks if `x` is a construct.
Use this method instead of `instanceof` to properly detect `Construct` instances, even when the construct library is symlinked.
Explanation: in JavaScript, multiple copies of the `constructs` library on disk are seen as independent, completely different libraries. As a consequence, the class `Construct` in each copy of the `constructs` library is seen as a different class, and an instance of one class will not test as `instanceof` the other class. `npm install` will not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of the `constructs` library can be accidentally installed, and `instanceof` will behave unpredictably. It is safest to avoid using `instanceof`, and using this type-testing method instead.
Returns: true if `x` is an object created from a class which extends `Construct`.
func CfnTemplate_CFN_RESOURCE_TYPE_NAME ¶
func CfnTemplate_CFN_RESOURCE_TYPE_NAME() *string
func CfnTemplate_IsCfnElement ¶
func CfnTemplate_IsCfnElement(x interface{}) *bool
Returns `true` if a construct is a stack element (i.e. part of the synthesized cloudformation template).
Uses duck-typing instead of `instanceof` to allow stack elements from different versions of this library to be included in the same stack.
Returns: The construct as a stack element or undefined if it is not a stack element.
func CfnTemplate_IsCfnResource ¶
func CfnTemplate_IsCfnResource(construct constructs.IConstruct) *bool
Check whether the given construct is a CfnResource.
func CfnTemplate_IsConstruct ¶
func CfnTemplate_IsConstruct(x interface{}) *bool
Checks if `x` is a construct.
Use this method instead of `instanceof` to properly detect `Construct` instances, even when the construct library is symlinked.
Explanation: in JavaScript, multiple copies of the `constructs` library on disk are seen as independent, completely different libraries. As a consequence, the class `Construct` in each copy of the `constructs` library is seen as a different class, and an instance of one class will not test as `instanceof` the other class. `npm install` will not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of the `constructs` library can be accidentally installed, and `instanceof` will behave unpredictably. It is safest to avoid using `instanceof`, and using this type-testing method instead.
Returns: true if `x` is an object created from a class which extends `Construct`.
func NewCfnConnector_Override ¶
func NewCfnConnector_Override(c CfnConnector, scope constructs.Construct, id *string, props *CfnConnectorProps)
func NewCfnDirectoryRegistration_Override ¶
func NewCfnDirectoryRegistration_Override(c CfnDirectoryRegistration, scope constructs.Construct, id *string, props *CfnDirectoryRegistrationProps)
func NewCfnServicePrincipalName_Override ¶
func NewCfnServicePrincipalName_Override(c CfnServicePrincipalName, scope constructs.Construct, id *string, props *CfnServicePrincipalNameProps)
func NewCfnTemplateGroupAccessControlEntry_Override ¶
func NewCfnTemplateGroupAccessControlEntry_Override(c CfnTemplateGroupAccessControlEntry, scope constructs.Construct, id *string, props *CfnTemplateGroupAccessControlEntryProps)
func NewCfnTemplate_Override ¶
func NewCfnTemplate_Override(c CfnTemplate, scope constructs.Construct, id *string, props *CfnTemplateProps)
Types ¶
type CfnConnector ¶
type CfnConnector interface { awscdk.CfnResource awscdk.IInspectable // The Amazon Resource Name (ARN) that was returned when you called [CreateConnector](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateConnector.html) . AttrConnectorArn() *string // The Amazon Resource Name (ARN) of the certificate authority being used. CertificateAuthorityArn() *string SetCertificateAuthorityArn(val *string) // Options for this resource, such as condition, update policy etc. CfnOptions() awscdk.ICfnResourceOptions CfnProperties() *map[string]interface{} // AWS resource type. CfnResourceType() *string // Returns: the stack trace of the point where this Resource was created from, sourced // from the +metadata+ entry typed +aws:cdk:logicalId+, and with the bottom-most // node +internal+ entries filtered. CreationStack() *[]*string // The identifier of the Active Directory. DirectoryId() *string SetDirectoryId(val *string) // The logical ID for this CloudFormation stack element. // // The logical ID of the element // is calculated from the path of the resource node in the construct tree. // // To override this value, use `overrideLogicalId(newLogicalId)`. // // Returns: the logical ID as a stringified token. This value will only get // resolved during synthesis. LogicalId() *string // The tree node. Node() constructs.Node // Return a string that will be resolved to a CloudFormation `{ Ref }` for this element. // // If, by any chance, the intrinsic reference of a resource is not a string, you could // coerce it to an IResolvable through `Lazy.any({ produce: resource.ref })`. Ref() *string // The stack in which this element is defined. // // CfnElements must be defined within a stack scope (directly or indirectly). Stack() awscdk.Stack // Metadata assigned to a connector consisting of a key-value pair. Tags() *map[string]*string SetTags(val *map[string]*string) // Deprecated. // Deprecated: use `updatedProperties` // // Return properties modified after initiation // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperites() *map[string]interface{} // Return properties modified after initiation. // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperties() *map[string]interface{} // Information of the VPC and security group(s) used with the connector. VpcInformation() interface{} SetVpcInformation(val interface{}) // Syntactic sugar for `addOverride(path, undefined)`. AddDeletionOverride(path *string) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // // This can be used for resources across stacks (or nested stack) boundaries // and the dependency will automatically be transferred to the relevant scope. AddDependency(target awscdk.CfnResource) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // Deprecated: use addDependency. AddDependsOn(target awscdk.CfnResource) // Add a value to the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // AddMetadata(key *string, value interface{}) // Adds an override to the synthesized CloudFormation resource. // // To add a // property override, either use `addPropertyOverride` or prefix `path` with // "Properties." (i.e. `Properties.TopicName`). // // If the override is nested, separate each nested level using a dot (.) in the path parameter. // If there is an array as part of the nesting, specify the index in the path. // // To include a literal `.` in the property name, prefix with a `\`. In most // programming languages you will need to write this as `"\\."` because the // `\` itself will need to be escaped. // // For example, // “`typescript // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes', ['myattribute']); // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.1.ProjectionType', 'INCLUDE'); // “` // would add the overrides // “`json // "Properties": { // "GlobalSecondaryIndexes": [ // { // "Projection": { // "NonKeyAttributes": [ "myattribute" ] // ... // } // ... // }, // { // "ProjectionType": "INCLUDE" // ... // }, // ] // ... // } // “` // // The `value` argument to `addOverride` will not be processed or translated // in any way. Pass raw JSON values in here with the correct capitalization // for CloudFormation. If you pass CDK classes or structs, they will be // rendered with lowercased key names, and CloudFormation will reject the // template. AddOverride(path *string, value interface{}) // Adds an override that deletes the value of a property from the resource definition. AddPropertyDeletionOverride(propertyPath *string) // Adds an override to a resource property. // // Syntactic sugar for `addOverride("Properties.<...>", value)`. AddPropertyOverride(propertyPath *string, value interface{}) // Sets the deletion policy of the resource based on the removal policy specified. // // The Removal Policy controls what happens to this resource when it stops // being managed by CloudFormation, either because you've removed it from the // CDK application or because you've made a change that requires the resource // to be replaced. // // The resource can be deleted (`RemovalPolicy.DESTROY`), or left in your AWS // account for data recovery and cleanup later (`RemovalPolicy.RETAIN`). In some // cases, a snapshot can be taken of the resource prior to deletion // (`RemovalPolicy.SNAPSHOT`). A list of resources that support this policy // can be found in the following link:. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-attribute-deletionpolicy.html#aws-attribute-deletionpolicy-options // ApplyRemovalPolicy(policy awscdk.RemovalPolicy, options *awscdk.RemovalPolicyOptions) // Returns a token for an runtime attribute of this resource. // // Ideally, use generated attribute accessors (e.g. `resource.arn`), but this can be used for future compatibility // in case there is no generated attribute. GetAtt(attributeName *string, typeHint awscdk.ResolutionTypeHint) awscdk.Reference // Retrieve a value value from the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // GetMetadata(key *string) interface{} // Examines the CloudFormation resource and discloses attributes. Inspect(inspector awscdk.TreeInspector) // Retrieves an array of resources this resource depends on. // // This assembles dependencies on resources across stacks (including nested stacks) // automatically. ObtainDependencies() *[]interface{} // Get a shallow copy of dependencies between this resource and other resources in the same stack. ObtainResourceDependencies() *[]awscdk.CfnResource // Overrides the auto-generated logical ID with a specific ID. OverrideLogicalId(newLogicalId *string) // Indicates that this resource no longer depends on another resource. // // This can be used for resources across stacks (including nested stacks) // and the dependency will automatically be removed from the relevant scope. RemoveDependency(target awscdk.CfnResource) RenderProperties(props *map[string]interface{}) *map[string]interface{} // Replaces one dependency with another. ReplaceDependency(target awscdk.CfnResource, newTarget awscdk.CfnResource) // Can be overridden by subclasses to determine if this resource will be rendered into the cloudformation template. // // Returns: `true` if the resource should be included or `false` is the resource // should be omitted. ShouldSynthesize() *bool // Returns a string representation of this construct. // // Returns: a string representation of this resource. ToString() *string ValidateProperties(_properties interface{}) }
Creates a connector between AWS Private CA and an Active Directory.
You must specify the private CA, directory ID, and security groups.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnConnector := awscdk.Aws_pcaconnectorad.NewCfnConnector(this, jsii.String("MyCfnConnector"), &CfnConnectorProps{ CertificateAuthorityArn: jsii.String("certificateAuthorityArn"), DirectoryId: jsii.String("directoryId"), VpcInformation: &VpcInformationProperty{ SecurityGroupIds: []*string{ jsii.String("securityGroupIds"), }, }, // the properties below are optional Tags: map[string]*string{ "tagsKey": jsii.String("tags"), }, })
func NewCfnConnector ¶
func NewCfnConnector(scope constructs.Construct, id *string, props *CfnConnectorProps) CfnConnector
type CfnConnectorProps ¶
type CfnConnectorProps struct { // The Amazon Resource Name (ARN) of the certificate authority being used. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-connector.html#cfn-pcaconnectorad-connector-certificateauthorityarn // CertificateAuthorityArn *string `field:"required" json:"certificateAuthorityArn" yaml:"certificateAuthorityArn"` // The identifier of the Active Directory. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-connector.html#cfn-pcaconnectorad-connector-directoryid // DirectoryId *string `field:"required" json:"directoryId" yaml:"directoryId"` // Information of the VPC and security group(s) used with the connector. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-connector.html#cfn-pcaconnectorad-connector-vpcinformation // VpcInformation interface{} `field:"required" json:"vpcInformation" yaml:"vpcInformation"` // Metadata assigned to a connector consisting of a key-value pair. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-connector.html#cfn-pcaconnectorad-connector-tags // Tags *map[string]*string `field:"optional" json:"tags" yaml:"tags"` }
Properties for defining a `CfnConnector`.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnConnectorProps := &CfnConnectorProps{ CertificateAuthorityArn: jsii.String("certificateAuthorityArn"), DirectoryId: jsii.String("directoryId"), VpcInformation: &VpcInformationProperty{ SecurityGroupIds: []*string{ jsii.String("securityGroupIds"), }, }, // the properties below are optional Tags: map[string]*string{ "tagsKey": jsii.String("tags"), }, }
type CfnConnector_VpcInformationProperty ¶
type CfnConnector_VpcInformationProperty struct { // The security groups used with the connector. // // You can use a maximum of 4 security groups with a connector. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-connector-vpcinformation.html#cfn-pcaconnectorad-connector-vpcinformation-securitygroupids // SecurityGroupIds *[]*string `field:"required" json:"securityGroupIds" yaml:"securityGroupIds"` }
Information about your VPC and security groups used with the connector.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" vpcInformationProperty := &VpcInformationProperty{ SecurityGroupIds: []*string{ jsii.String("securityGroupIds"), }, }
type CfnDirectoryRegistration ¶
type CfnDirectoryRegistration interface { awscdk.CfnResource awscdk.IInspectable // The Amazon Resource Name (ARN) that was returned when you called [CreateDirectoryRegistration](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateDirectoryRegistration.html) . AttrDirectoryRegistrationArn() *string // Options for this resource, such as condition, update policy etc. CfnOptions() awscdk.ICfnResourceOptions CfnProperties() *map[string]interface{} // AWS resource type. CfnResourceType() *string // Returns: the stack trace of the point where this Resource was created from, sourced // from the +metadata+ entry typed +aws:cdk:logicalId+, and with the bottom-most // node +internal+ entries filtered. CreationStack() *[]*string // The identifier of the Active Directory. DirectoryId() *string SetDirectoryId(val *string) // The logical ID for this CloudFormation stack element. // // The logical ID of the element // is calculated from the path of the resource node in the construct tree. // // To override this value, use `overrideLogicalId(newLogicalId)`. // // Returns: the logical ID as a stringified token. This value will only get // resolved during synthesis. LogicalId() *string // The tree node. Node() constructs.Node // Return a string that will be resolved to a CloudFormation `{ Ref }` for this element. // // If, by any chance, the intrinsic reference of a resource is not a string, you could // coerce it to an IResolvable through `Lazy.any({ produce: resource.ref })`. Ref() *string // The stack in which this element is defined. // // CfnElements must be defined within a stack scope (directly or indirectly). Stack() awscdk.Stack // Metadata assigned to a directory registration consisting of a key-value pair. Tags() *map[string]*string SetTags(val *map[string]*string) // Deprecated. // Deprecated: use `updatedProperties` // // Return properties modified after initiation // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperites() *map[string]interface{} // Return properties modified after initiation. // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperties() *map[string]interface{} // Syntactic sugar for `addOverride(path, undefined)`. AddDeletionOverride(path *string) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // // This can be used for resources across stacks (or nested stack) boundaries // and the dependency will automatically be transferred to the relevant scope. AddDependency(target awscdk.CfnResource) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // Deprecated: use addDependency. AddDependsOn(target awscdk.CfnResource) // Add a value to the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // AddMetadata(key *string, value interface{}) // Adds an override to the synthesized CloudFormation resource. // // To add a // property override, either use `addPropertyOverride` or prefix `path` with // "Properties." (i.e. `Properties.TopicName`). // // If the override is nested, separate each nested level using a dot (.) in the path parameter. // If there is an array as part of the nesting, specify the index in the path. // // To include a literal `.` in the property name, prefix with a `\`. In most // programming languages you will need to write this as `"\\."` because the // `\` itself will need to be escaped. // // For example, // “`typescript // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes', ['myattribute']); // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.1.ProjectionType', 'INCLUDE'); // “` // would add the overrides // “`json // "Properties": { // "GlobalSecondaryIndexes": [ // { // "Projection": { // "NonKeyAttributes": [ "myattribute" ] // ... // } // ... // }, // { // "ProjectionType": "INCLUDE" // ... // }, // ] // ... // } // “` // // The `value` argument to `addOverride` will not be processed or translated // in any way. Pass raw JSON values in here with the correct capitalization // for CloudFormation. If you pass CDK classes or structs, they will be // rendered with lowercased key names, and CloudFormation will reject the // template. AddOverride(path *string, value interface{}) // Adds an override that deletes the value of a property from the resource definition. AddPropertyDeletionOverride(propertyPath *string) // Adds an override to a resource property. // // Syntactic sugar for `addOverride("Properties.<...>", value)`. AddPropertyOverride(propertyPath *string, value interface{}) // Sets the deletion policy of the resource based on the removal policy specified. // // The Removal Policy controls what happens to this resource when it stops // being managed by CloudFormation, either because you've removed it from the // CDK application or because you've made a change that requires the resource // to be replaced. // // The resource can be deleted (`RemovalPolicy.DESTROY`), or left in your AWS // account for data recovery and cleanup later (`RemovalPolicy.RETAIN`). In some // cases, a snapshot can be taken of the resource prior to deletion // (`RemovalPolicy.SNAPSHOT`). A list of resources that support this policy // can be found in the following link:. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-attribute-deletionpolicy.html#aws-attribute-deletionpolicy-options // ApplyRemovalPolicy(policy awscdk.RemovalPolicy, options *awscdk.RemovalPolicyOptions) // Returns a token for an runtime attribute of this resource. // // Ideally, use generated attribute accessors (e.g. `resource.arn`), but this can be used for future compatibility // in case there is no generated attribute. GetAtt(attributeName *string, typeHint awscdk.ResolutionTypeHint) awscdk.Reference // Retrieve a value value from the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // GetMetadata(key *string) interface{} // Examines the CloudFormation resource and discloses attributes. Inspect(inspector awscdk.TreeInspector) // Retrieves an array of resources this resource depends on. // // This assembles dependencies on resources across stacks (including nested stacks) // automatically. ObtainDependencies() *[]interface{} // Get a shallow copy of dependencies between this resource and other resources in the same stack. ObtainResourceDependencies() *[]awscdk.CfnResource // Overrides the auto-generated logical ID with a specific ID. OverrideLogicalId(newLogicalId *string) // Indicates that this resource no longer depends on another resource. // // This can be used for resources across stacks (including nested stacks) // and the dependency will automatically be removed from the relevant scope. RemoveDependency(target awscdk.CfnResource) RenderProperties(props *map[string]interface{}) *map[string]interface{} // Replaces one dependency with another. ReplaceDependency(target awscdk.CfnResource, newTarget awscdk.CfnResource) // Can be overridden by subclasses to determine if this resource will be rendered into the cloudformation template. // // Returns: `true` if the resource should be included or `false` is the resource // should be omitted. ShouldSynthesize() *bool // Returns a string representation of this construct. // // Returns: a string representation of this resource. ToString() *string ValidateProperties(_properties interface{}) }
Creates a directory registration that authorizes communication between AWS Private CA and an Active Directory.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnDirectoryRegistration := awscdk.Aws_pcaconnectorad.NewCfnDirectoryRegistration(this, jsii.String("MyCfnDirectoryRegistration"), &CfnDirectoryRegistrationProps{ DirectoryId: jsii.String("directoryId"), // the properties below are optional Tags: map[string]*string{ "tagsKey": jsii.String("tags"), }, })
func NewCfnDirectoryRegistration ¶
func NewCfnDirectoryRegistration(scope constructs.Construct, id *string, props *CfnDirectoryRegistrationProps) CfnDirectoryRegistration
type CfnDirectoryRegistrationProps ¶
type CfnDirectoryRegistrationProps struct { // The identifier of the Active Directory. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-directoryregistration.html#cfn-pcaconnectorad-directoryregistration-directoryid // DirectoryId *string `field:"required" json:"directoryId" yaml:"directoryId"` // Metadata assigned to a directory registration consisting of a key-value pair. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-directoryregistration.html#cfn-pcaconnectorad-directoryregistration-tags // Tags *map[string]*string `field:"optional" json:"tags" yaml:"tags"` }
Properties for defining a `CfnDirectoryRegistration`.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnDirectoryRegistrationProps := &CfnDirectoryRegistrationProps{ DirectoryId: jsii.String("directoryId"), // the properties below are optional Tags: map[string]*string{ "tagsKey": jsii.String("tags"), }, }
type CfnServicePrincipalName ¶
type CfnServicePrincipalName interface { awscdk.CfnResource awscdk.IInspectable // Options for this resource, such as condition, update policy etc. CfnOptions() awscdk.ICfnResourceOptions CfnProperties() *map[string]interface{} // AWS resource type. CfnResourceType() *string // The Amazon Resource Name (ARN) that was returned when you called [CreateConnector.html](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateConnector.html) . ConnectorArn() *string SetConnectorArn(val *string) // Returns: the stack trace of the point where this Resource was created from, sourced // from the +metadata+ entry typed +aws:cdk:logicalId+, and with the bottom-most // node +internal+ entries filtered. CreationStack() *[]*string // The Amazon Resource Name (ARN) that was returned when you called [CreateDirectoryRegistration](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateDirectoryRegistration.html) . DirectoryRegistrationArn() *string SetDirectoryRegistrationArn(val *string) // The logical ID for this CloudFormation stack element. // // The logical ID of the element // is calculated from the path of the resource node in the construct tree. // // To override this value, use `overrideLogicalId(newLogicalId)`. // // Returns: the logical ID as a stringified token. This value will only get // resolved during synthesis. LogicalId() *string // The tree node. Node() constructs.Node // Return a string that will be resolved to a CloudFormation `{ Ref }` for this element. // // If, by any chance, the intrinsic reference of a resource is not a string, you could // coerce it to an IResolvable through `Lazy.any({ produce: resource.ref })`. Ref() *string // The stack in which this element is defined. // // CfnElements must be defined within a stack scope (directly or indirectly). Stack() awscdk.Stack // Deprecated. // Deprecated: use `updatedProperties` // // Return properties modified after initiation // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperites() *map[string]interface{} // Return properties modified after initiation. // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperties() *map[string]interface{} // Syntactic sugar for `addOverride(path, undefined)`. AddDeletionOverride(path *string) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // // This can be used for resources across stacks (or nested stack) boundaries // and the dependency will automatically be transferred to the relevant scope. AddDependency(target awscdk.CfnResource) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // Deprecated: use addDependency. AddDependsOn(target awscdk.CfnResource) // Add a value to the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // AddMetadata(key *string, value interface{}) // Adds an override to the synthesized CloudFormation resource. // // To add a // property override, either use `addPropertyOverride` or prefix `path` with // "Properties." (i.e. `Properties.TopicName`). // // If the override is nested, separate each nested level using a dot (.) in the path parameter. // If there is an array as part of the nesting, specify the index in the path. // // To include a literal `.` in the property name, prefix with a `\`. In most // programming languages you will need to write this as `"\\."` because the // `\` itself will need to be escaped. // // For example, // “`typescript // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes', ['myattribute']); // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.1.ProjectionType', 'INCLUDE'); // “` // would add the overrides // “`json // "Properties": { // "GlobalSecondaryIndexes": [ // { // "Projection": { // "NonKeyAttributes": [ "myattribute" ] // ... // } // ... // }, // { // "ProjectionType": "INCLUDE" // ... // }, // ] // ... // } // “` // // The `value` argument to `addOverride` will not be processed or translated // in any way. Pass raw JSON values in here with the correct capitalization // for CloudFormation. If you pass CDK classes or structs, they will be // rendered with lowercased key names, and CloudFormation will reject the // template. AddOverride(path *string, value interface{}) // Adds an override that deletes the value of a property from the resource definition. AddPropertyDeletionOverride(propertyPath *string) // Adds an override to a resource property. // // Syntactic sugar for `addOverride("Properties.<...>", value)`. AddPropertyOverride(propertyPath *string, value interface{}) // Sets the deletion policy of the resource based on the removal policy specified. // // The Removal Policy controls what happens to this resource when it stops // being managed by CloudFormation, either because you've removed it from the // CDK application or because you've made a change that requires the resource // to be replaced. // // The resource can be deleted (`RemovalPolicy.DESTROY`), or left in your AWS // account for data recovery and cleanup later (`RemovalPolicy.RETAIN`). In some // cases, a snapshot can be taken of the resource prior to deletion // (`RemovalPolicy.SNAPSHOT`). A list of resources that support this policy // can be found in the following link:. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-attribute-deletionpolicy.html#aws-attribute-deletionpolicy-options // ApplyRemovalPolicy(policy awscdk.RemovalPolicy, options *awscdk.RemovalPolicyOptions) // Returns a token for an runtime attribute of this resource. // // Ideally, use generated attribute accessors (e.g. `resource.arn`), but this can be used for future compatibility // in case there is no generated attribute. GetAtt(attributeName *string, typeHint awscdk.ResolutionTypeHint) awscdk.Reference // Retrieve a value value from the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // GetMetadata(key *string) interface{} // Examines the CloudFormation resource and discloses attributes. Inspect(inspector awscdk.TreeInspector) // Retrieves an array of resources this resource depends on. // // This assembles dependencies on resources across stacks (including nested stacks) // automatically. ObtainDependencies() *[]interface{} // Get a shallow copy of dependencies between this resource and other resources in the same stack. ObtainResourceDependencies() *[]awscdk.CfnResource // Overrides the auto-generated logical ID with a specific ID. OverrideLogicalId(newLogicalId *string) // Indicates that this resource no longer depends on another resource. // // This can be used for resources across stacks (including nested stacks) // and the dependency will automatically be removed from the relevant scope. RemoveDependency(target awscdk.CfnResource) RenderProperties(props *map[string]interface{}) *map[string]interface{} // Replaces one dependency with another. ReplaceDependency(target awscdk.CfnResource, newTarget awscdk.CfnResource) // Can be overridden by subclasses to determine if this resource will be rendered into the cloudformation template. // // Returns: `true` if the resource should be included or `false` is the resource // should be omitted. ShouldSynthesize() *bool // Returns a string representation of this construct. // // Returns: a string representation of this resource. ToString() *string ValidateProperties(_properties interface{}) }
Creates a service principal name (SPN) for the service account in Active Directory.
Kerberos authentication uses SPNs to associate a service instance with a service sign-in account.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnServicePrincipalName := awscdk.Aws_pcaconnectorad.NewCfnServicePrincipalName(this, jsii.String("MyCfnServicePrincipalName"), &CfnServicePrincipalNameProps{ ConnectorArn: jsii.String("connectorArn"), DirectoryRegistrationArn: jsii.String("directoryRegistrationArn"), })
func NewCfnServicePrincipalName ¶
func NewCfnServicePrincipalName(scope constructs.Construct, id *string, props *CfnServicePrincipalNameProps) CfnServicePrincipalName
type CfnServicePrincipalNameProps ¶
type CfnServicePrincipalNameProps struct { // The Amazon Resource Name (ARN) that was returned when you called [CreateConnector.html](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateConnector.html) . // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-serviceprincipalname.html#cfn-pcaconnectorad-serviceprincipalname-connectorarn // ConnectorArn *string `field:"optional" json:"connectorArn" yaml:"connectorArn"` // The Amazon Resource Name (ARN) that was returned when you called [CreateDirectoryRegistration](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateDirectoryRegistration.html) . // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-serviceprincipalname.html#cfn-pcaconnectorad-serviceprincipalname-directoryregistrationarn // DirectoryRegistrationArn *string `field:"optional" json:"directoryRegistrationArn" yaml:"directoryRegistrationArn"` }
Properties for defining a `CfnServicePrincipalName`.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnServicePrincipalNameProps := &CfnServicePrincipalNameProps{ ConnectorArn: jsii.String("connectorArn"), DirectoryRegistrationArn: jsii.String("directoryRegistrationArn"), }
type CfnTemplate ¶
type CfnTemplate interface { awscdk.CfnResource awscdk.IInspectable // The Amazon Resource Name (ARN) that was returned when you called [CreateTemplate](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateTemplate.html) . AttrTemplateArn() *string // Options for this resource, such as condition, update policy etc. CfnOptions() awscdk.ICfnResourceOptions CfnProperties() *map[string]interface{} // AWS resource type. CfnResourceType() *string // The Amazon Resource Name (ARN) that was returned when you called [CreateConnector](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateConnector.html) . ConnectorArn() *string SetConnectorArn(val *string) // Returns: the stack trace of the point where this Resource was created from, sourced // from the +metadata+ entry typed +aws:cdk:logicalId+, and with the bottom-most // node +internal+ entries filtered. CreationStack() *[]*string // Template configuration to define the information included in certificates. Definition() interface{} SetDefinition(val interface{}) // The logical ID for this CloudFormation stack element. // // The logical ID of the element // is calculated from the path of the resource node in the construct tree. // // To override this value, use `overrideLogicalId(newLogicalId)`. // // Returns: the logical ID as a stringified token. This value will only get // resolved during synthesis. LogicalId() *string // Name of the templates. Name() *string SetName(val *string) // The tree node. Node() constructs.Node // This setting allows the major version of a template to be increased automatically. ReenrollAllCertificateHolders() interface{} SetReenrollAllCertificateHolders(val interface{}) // Return a string that will be resolved to a CloudFormation `{ Ref }` for this element. // // If, by any chance, the intrinsic reference of a resource is not a string, you could // coerce it to an IResolvable through `Lazy.any({ produce: resource.ref })`. Ref() *string // The stack in which this element is defined. // // CfnElements must be defined within a stack scope (directly or indirectly). Stack() awscdk.Stack // Metadata assigned to a template consisting of a key-value pair. Tags() *map[string]*string SetTags(val *map[string]*string) // Deprecated. // Deprecated: use `updatedProperties` // // Return properties modified after initiation // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperites() *map[string]interface{} // Return properties modified after initiation. // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperties() *map[string]interface{} // Syntactic sugar for `addOverride(path, undefined)`. AddDeletionOverride(path *string) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // // This can be used for resources across stacks (or nested stack) boundaries // and the dependency will automatically be transferred to the relevant scope. AddDependency(target awscdk.CfnResource) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // Deprecated: use addDependency. AddDependsOn(target awscdk.CfnResource) // Add a value to the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // AddMetadata(key *string, value interface{}) // Adds an override to the synthesized CloudFormation resource. // // To add a // property override, either use `addPropertyOverride` or prefix `path` with // "Properties." (i.e. `Properties.TopicName`). // // If the override is nested, separate each nested level using a dot (.) in the path parameter. // If there is an array as part of the nesting, specify the index in the path. // // To include a literal `.` in the property name, prefix with a `\`. In most // programming languages you will need to write this as `"\\."` because the // `\` itself will need to be escaped. // // For example, // “`typescript // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes', ['myattribute']); // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.1.ProjectionType', 'INCLUDE'); // “` // would add the overrides // “`json // "Properties": { // "GlobalSecondaryIndexes": [ // { // "Projection": { // "NonKeyAttributes": [ "myattribute" ] // ... // } // ... // }, // { // "ProjectionType": "INCLUDE" // ... // }, // ] // ... // } // “` // // The `value` argument to `addOverride` will not be processed or translated // in any way. Pass raw JSON values in here with the correct capitalization // for CloudFormation. If you pass CDK classes or structs, they will be // rendered with lowercased key names, and CloudFormation will reject the // template. AddOverride(path *string, value interface{}) // Adds an override that deletes the value of a property from the resource definition. AddPropertyDeletionOverride(propertyPath *string) // Adds an override to a resource property. // // Syntactic sugar for `addOverride("Properties.<...>", value)`. AddPropertyOverride(propertyPath *string, value interface{}) // Sets the deletion policy of the resource based on the removal policy specified. // // The Removal Policy controls what happens to this resource when it stops // being managed by CloudFormation, either because you've removed it from the // CDK application or because you've made a change that requires the resource // to be replaced. // // The resource can be deleted (`RemovalPolicy.DESTROY`), or left in your AWS // account for data recovery and cleanup later (`RemovalPolicy.RETAIN`). In some // cases, a snapshot can be taken of the resource prior to deletion // (`RemovalPolicy.SNAPSHOT`). A list of resources that support this policy // can be found in the following link:. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-attribute-deletionpolicy.html#aws-attribute-deletionpolicy-options // ApplyRemovalPolicy(policy awscdk.RemovalPolicy, options *awscdk.RemovalPolicyOptions) // Returns a token for an runtime attribute of this resource. // // Ideally, use generated attribute accessors (e.g. `resource.arn`), but this can be used for future compatibility // in case there is no generated attribute. GetAtt(attributeName *string, typeHint awscdk.ResolutionTypeHint) awscdk.Reference // Retrieve a value value from the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // GetMetadata(key *string) interface{} // Examines the CloudFormation resource and discloses attributes. Inspect(inspector awscdk.TreeInspector) // Retrieves an array of resources this resource depends on. // // This assembles dependencies on resources across stacks (including nested stacks) // automatically. ObtainDependencies() *[]interface{} // Get a shallow copy of dependencies between this resource and other resources in the same stack. ObtainResourceDependencies() *[]awscdk.CfnResource // Overrides the auto-generated logical ID with a specific ID. OverrideLogicalId(newLogicalId *string) // Indicates that this resource no longer depends on another resource. // // This can be used for resources across stacks (including nested stacks) // and the dependency will automatically be removed from the relevant scope. RemoveDependency(target awscdk.CfnResource) RenderProperties(props *map[string]interface{}) *map[string]interface{} // Replaces one dependency with another. ReplaceDependency(target awscdk.CfnResource, newTarget awscdk.CfnResource) // Can be overridden by subclasses to determine if this resource will be rendered into the cloudformation template. // // Returns: `true` if the resource should be included or `false` is the resource // should be omitted. ShouldSynthesize() *bool // Returns a string representation of this construct. // // Returns: a string representation of this resource. ToString() *string ValidateProperties(_properties interface{}) }
Creates an Active Directory compatible certificate template.
The connectors issues certificates using these templates based on the requester’s Active Directory group membership.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnTemplate := awscdk.Aws_pcaconnectorad.NewCfnTemplate(this, jsii.String("MyCfnTemplate"), &CfnTemplateProps{ ConnectorArn: jsii.String("connectorArn"), Definition: &TemplateDefinitionProperty{ TemplateV2: &TemplateV2Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV2Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV2Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV2Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV2Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV2Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV2Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, TemplateV3: &TemplateV3Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV3Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV3Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV3Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, HashAlgorithm: jsii.String("hashAlgorithm"), PrivateKeyAttributes: &PrivateKeyAttributesV3Property{ Algorithm: jsii.String("algorithm"), KeySpec: jsii.String("keySpec"), KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV3Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV3Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, TemplateV4: &TemplateV4Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV4Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV4Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV4Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV4Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional Algorithm: jsii.String("algorithm"), CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV4Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), RequireSameKeyRenewal: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), UseLegacyProvider: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV4Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional HashAlgorithm: jsii.String("hashAlgorithm"), SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, }, Name: jsii.String("name"), // the properties below are optional ReenrollAllCertificateHolders: jsii.Boolean(false), Tags: map[string]*string{ "tagsKey": jsii.String("tags"), }, })
func NewCfnTemplate ¶
func NewCfnTemplate(scope constructs.Construct, id *string, props *CfnTemplateProps) CfnTemplate
type CfnTemplateGroupAccessControlEntry ¶
type CfnTemplateGroupAccessControlEntry interface { awscdk.CfnResource awscdk.IInspectable // Permissions to allow or deny an Active Directory group to enroll or autoenroll certificates issued against a template. AccessRights() interface{} SetAccessRights(val interface{}) // Options for this resource, such as condition, update policy etc. CfnOptions() awscdk.ICfnResourceOptions CfnProperties() *map[string]interface{} // AWS resource type. CfnResourceType() *string // Returns: the stack trace of the point where this Resource was created from, sourced // from the +metadata+ entry typed +aws:cdk:logicalId+, and with the bottom-most // node +internal+ entries filtered. CreationStack() *[]*string // Name of the Active Directory group. GroupDisplayName() *string SetGroupDisplayName(val *string) // Security identifier (SID) of the group object from Active Directory. GroupSecurityIdentifier() *string SetGroupSecurityIdentifier(val *string) // The logical ID for this CloudFormation stack element. // // The logical ID of the element // is calculated from the path of the resource node in the construct tree. // // To override this value, use `overrideLogicalId(newLogicalId)`. // // Returns: the logical ID as a stringified token. This value will only get // resolved during synthesis. LogicalId() *string // The tree node. Node() constructs.Node // Return a string that will be resolved to a CloudFormation `{ Ref }` for this element. // // If, by any chance, the intrinsic reference of a resource is not a string, you could // coerce it to an IResolvable through `Lazy.any({ produce: resource.ref })`. Ref() *string // The stack in which this element is defined. // // CfnElements must be defined within a stack scope (directly or indirectly). Stack() awscdk.Stack // The Amazon Resource Name (ARN) that was returned when you called [CreateTemplate](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateTemplate.html) . TemplateArn() *string SetTemplateArn(val *string) // Deprecated. // Deprecated: use `updatedProperties` // // Return properties modified after initiation // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperites() *map[string]interface{} // Return properties modified after initiation. // // Resources that expose mutable properties should override this function to // collect and return the properties object for this resource. UpdatedProperties() *map[string]interface{} // Syntactic sugar for `addOverride(path, undefined)`. AddDeletionOverride(path *string) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // // This can be used for resources across stacks (or nested stack) boundaries // and the dependency will automatically be transferred to the relevant scope. AddDependency(target awscdk.CfnResource) // Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. // Deprecated: use addDependency. AddDependsOn(target awscdk.CfnResource) // Add a value to the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // AddMetadata(key *string, value interface{}) // Adds an override to the synthesized CloudFormation resource. // // To add a // property override, either use `addPropertyOverride` or prefix `path` with // "Properties." (i.e. `Properties.TopicName`). // // If the override is nested, separate each nested level using a dot (.) in the path parameter. // If there is an array as part of the nesting, specify the index in the path. // // To include a literal `.` in the property name, prefix with a `\`. In most // programming languages you will need to write this as `"\\."` because the // `\` itself will need to be escaped. // // For example, // “`typescript // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes', ['myattribute']); // cfnResource.addOverride('Properties.GlobalSecondaryIndexes.1.ProjectionType', 'INCLUDE'); // “` // would add the overrides // “`json // "Properties": { // "GlobalSecondaryIndexes": [ // { // "Projection": { // "NonKeyAttributes": [ "myattribute" ] // ... // } // ... // }, // { // "ProjectionType": "INCLUDE" // ... // }, // ] // ... // } // “` // // The `value` argument to `addOverride` will not be processed or translated // in any way. Pass raw JSON values in here with the correct capitalization // for CloudFormation. If you pass CDK classes or structs, they will be // rendered with lowercased key names, and CloudFormation will reject the // template. AddOverride(path *string, value interface{}) // Adds an override that deletes the value of a property from the resource definition. AddPropertyDeletionOverride(propertyPath *string) // Adds an override to a resource property. // // Syntactic sugar for `addOverride("Properties.<...>", value)`. AddPropertyOverride(propertyPath *string, value interface{}) // Sets the deletion policy of the resource based on the removal policy specified. // // The Removal Policy controls what happens to this resource when it stops // being managed by CloudFormation, either because you've removed it from the // CDK application or because you've made a change that requires the resource // to be replaced. // // The resource can be deleted (`RemovalPolicy.DESTROY`), or left in your AWS // account for data recovery and cleanup later (`RemovalPolicy.RETAIN`). In some // cases, a snapshot can be taken of the resource prior to deletion // (`RemovalPolicy.SNAPSHOT`). A list of resources that support this policy // can be found in the following link:. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-attribute-deletionpolicy.html#aws-attribute-deletionpolicy-options // ApplyRemovalPolicy(policy awscdk.RemovalPolicy, options *awscdk.RemovalPolicyOptions) // Returns a token for an runtime attribute of this resource. // // Ideally, use generated attribute accessors (e.g. `resource.arn`), but this can be used for future compatibility // in case there is no generated attribute. GetAtt(attributeName *string, typeHint awscdk.ResolutionTypeHint) awscdk.Reference // Retrieve a value value from the CloudFormation Resource Metadata. // See: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html // // Note that this is a different set of metadata from CDK node metadata; this // metadata ends up in the stack template under the resource, whereas CDK // node metadata ends up in the Cloud Assembly. // GetMetadata(key *string) interface{} // Examines the CloudFormation resource and discloses attributes. Inspect(inspector awscdk.TreeInspector) // Retrieves an array of resources this resource depends on. // // This assembles dependencies on resources across stacks (including nested stacks) // automatically. ObtainDependencies() *[]interface{} // Get a shallow copy of dependencies between this resource and other resources in the same stack. ObtainResourceDependencies() *[]awscdk.CfnResource // Overrides the auto-generated logical ID with a specific ID. OverrideLogicalId(newLogicalId *string) // Indicates that this resource no longer depends on another resource. // // This can be used for resources across stacks (including nested stacks) // and the dependency will automatically be removed from the relevant scope. RemoveDependency(target awscdk.CfnResource) RenderProperties(props *map[string]interface{}) *map[string]interface{} // Replaces one dependency with another. ReplaceDependency(target awscdk.CfnResource, newTarget awscdk.CfnResource) // Can be overridden by subclasses to determine if this resource will be rendered into the cloudformation template. // // Returns: `true` if the resource should be included or `false` is the resource // should be omitted. ShouldSynthesize() *bool // Returns a string representation of this construct. // // Returns: a string representation of this resource. ToString() *string ValidateProperties(_properties interface{}) }
Create a group access control entry.
Allow or deny Active Directory groups from enrolling and/or autoenrolling with the template based on the group security identifiers (SIDs).
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnTemplateGroupAccessControlEntry := awscdk.Aws_pcaconnectorad.NewCfnTemplateGroupAccessControlEntry(this, jsii.String("MyCfnTemplateGroupAccessControlEntry"), &CfnTemplateGroupAccessControlEntryProps{ AccessRights: &AccessRightsProperty{ AutoEnroll: jsii.String("autoEnroll"), Enroll: jsii.String("enroll"), }, GroupDisplayName: jsii.String("groupDisplayName"), // the properties below are optional GroupSecurityIdentifier: jsii.String("groupSecurityIdentifier"), TemplateArn: jsii.String("templateArn"), })
func NewCfnTemplateGroupAccessControlEntry ¶
func NewCfnTemplateGroupAccessControlEntry(scope constructs.Construct, id *string, props *CfnTemplateGroupAccessControlEntryProps) CfnTemplateGroupAccessControlEntry
type CfnTemplateGroupAccessControlEntryProps ¶
type CfnTemplateGroupAccessControlEntryProps struct { // Permissions to allow or deny an Active Directory group to enroll or autoenroll certificates issued against a template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-templategroupaccesscontrolentry.html#cfn-pcaconnectorad-templategroupaccesscontrolentry-accessrights // AccessRights interface{} `field:"required" json:"accessRights" yaml:"accessRights"` // Name of the Active Directory group. // // This name does not need to match the group name in Active Directory. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-templategroupaccesscontrolentry.html#cfn-pcaconnectorad-templategroupaccesscontrolentry-groupdisplayname // GroupDisplayName *string `field:"required" json:"groupDisplayName" yaml:"groupDisplayName"` // Security identifier (SID) of the group object from Active Directory. // // The SID starts with "S-". // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-templategroupaccesscontrolentry.html#cfn-pcaconnectorad-templategroupaccesscontrolentry-groupsecurityidentifier // GroupSecurityIdentifier *string `field:"optional" json:"groupSecurityIdentifier" yaml:"groupSecurityIdentifier"` // The Amazon Resource Name (ARN) that was returned when you called [CreateTemplate](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateTemplate.html) . // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-templategroupaccesscontrolentry.html#cfn-pcaconnectorad-templategroupaccesscontrolentry-templatearn // TemplateArn *string `field:"optional" json:"templateArn" yaml:"templateArn"` }
Properties for defining a `CfnTemplateGroupAccessControlEntry`.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnTemplateGroupAccessControlEntryProps := &CfnTemplateGroupAccessControlEntryProps{ AccessRights: &AccessRightsProperty{ AutoEnroll: jsii.String("autoEnroll"), Enroll: jsii.String("enroll"), }, GroupDisplayName: jsii.String("groupDisplayName"), // the properties below are optional GroupSecurityIdentifier: jsii.String("groupSecurityIdentifier"), TemplateArn: jsii.String("templateArn"), }
type CfnTemplateGroupAccessControlEntry_AccessRightsProperty ¶
type CfnTemplateGroupAccessControlEntry_AccessRightsProperty struct { // Allow or deny an Active Directory group from autoenrolling certificates issued against a template. // // The Active Directory group must be allowed to enroll to allow autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-templategroupaccesscontrolentry-accessrights.html#cfn-pcaconnectorad-templategroupaccesscontrolentry-accessrights-autoenroll // AutoEnroll *string `field:"optional" json:"autoEnroll" yaml:"autoEnroll"` // Allow or deny an Active Directory group from enrolling certificates issued against a template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-templategroupaccesscontrolentry-accessrights.html#cfn-pcaconnectorad-templategroupaccesscontrolentry-accessrights-enroll // Enroll *string `field:"optional" json:"enroll" yaml:"enroll"` }
Allow or deny permissions for an Active Directory group to enroll or autoenroll certificates for a template.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" accessRightsProperty := &AccessRightsProperty{ AutoEnroll: jsii.String("autoEnroll"), Enroll: jsii.String("enroll"), }
type CfnTemplateProps ¶
type CfnTemplateProps struct { // The Amazon Resource Name (ARN) that was returned when you called [CreateConnector](https://docs.aws.amazon.com/pca-connector-ad/latest/APIReference/API_CreateConnector.html) . // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-template.html#cfn-pcaconnectorad-template-connectorarn // ConnectorArn *string `field:"required" json:"connectorArn" yaml:"connectorArn"` // Template configuration to define the information included in certificates. // // Define certificate validity and renewal periods, certificate request handling and enrollment options, key usage extensions, application policies, and cryptography settings. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-template.html#cfn-pcaconnectorad-template-definition // Definition interface{} `field:"required" json:"definition" yaml:"definition"` // Name of the templates. // // Template names must be unique. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-template.html#cfn-pcaconnectorad-template-name // Name *string `field:"required" json:"name" yaml:"name"` // This setting allows the major version of a template to be increased automatically. // // All members of Active Directory groups that are allowed to enroll with a template will receive a new certificate issued using that template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-template.html#cfn-pcaconnectorad-template-reenrollallcertificateholders // ReenrollAllCertificateHolders interface{} `field:"optional" json:"reenrollAllCertificateHolders" yaml:"reenrollAllCertificateHolders"` // Metadata assigned to a template consisting of a key-value pair. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-pcaconnectorad-template.html#cfn-pcaconnectorad-template-tags // Tags *map[string]*string `field:"optional" json:"tags" yaml:"tags"` }
Properties for defining a `CfnTemplate`.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" cfnTemplateProps := &CfnTemplateProps{ ConnectorArn: jsii.String("connectorArn"), Definition: &TemplateDefinitionProperty{ TemplateV2: &TemplateV2Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV2Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV2Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV2Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV2Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV2Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV2Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, TemplateV3: &TemplateV3Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV3Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV3Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV3Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, HashAlgorithm: jsii.String("hashAlgorithm"), PrivateKeyAttributes: &PrivateKeyAttributesV3Property{ Algorithm: jsii.String("algorithm"), KeySpec: jsii.String("keySpec"), KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV3Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV3Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, TemplateV4: &TemplateV4Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV4Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV4Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV4Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV4Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional Algorithm: jsii.String("algorithm"), CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV4Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), RequireSameKeyRenewal: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), UseLegacyProvider: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV4Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional HashAlgorithm: jsii.String("hashAlgorithm"), SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, }, Name: jsii.String("name"), // the properties below are optional ReenrollAllCertificateHolders: jsii.Boolean(false), Tags: map[string]*string{ "tagsKey": jsii.String("tags"), }, }
type CfnTemplate_ApplicationPoliciesProperty ¶
type CfnTemplate_ApplicationPoliciesProperty struct { // Application policies describe what the certificate can be used for. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-applicationpolicies.html#cfn-pcaconnectorad-template-applicationpolicies-policies // Policies interface{} `field:"required" json:"policies" yaml:"policies"` // Marks the application policy extension as critical. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-applicationpolicies.html#cfn-pcaconnectorad-template-applicationpolicies-critical // Critical interface{} `field:"optional" json:"critical" yaml:"critical"` }
Application policies describe what the certificate can be used for.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" applicationPoliciesProperty := &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }
type CfnTemplate_ApplicationPolicyProperty ¶
type CfnTemplate_ApplicationPolicyProperty struct { // The object identifier (OID) of an application policy. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-applicationpolicy.html#cfn-pcaconnectorad-template-applicationpolicy-policyobjectidentifier // PolicyObjectIdentifier *string `field:"optional" json:"policyObjectIdentifier" yaml:"policyObjectIdentifier"` // The type of application policy. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-applicationpolicy.html#cfn-pcaconnectorad-template-applicationpolicy-policytype // PolicyType *string `field:"optional" json:"policyType" yaml:"policyType"` }
Application policies describe what the certificate can be used for.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" applicationPolicyProperty := &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }
type CfnTemplate_CertificateValidityProperty ¶
type CfnTemplate_CertificateValidityProperty struct { // Renewal period is the period of time before certificate expiration when a new certificate will be requested. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-certificatevalidity.html#cfn-pcaconnectorad-template-certificatevalidity-renewalperiod // RenewalPeriod interface{} `field:"required" json:"renewalPeriod" yaml:"renewalPeriod"` // Information describing the end of the validity period of the certificate. // // This parameter sets the “Not After” date for the certificate. Certificate validity is the period of time during which a certificate is valid. Validity can be expressed as an explicit date and time when the certificate expires, or as a span of time after issuance, stated in days, months, or years. For more information, see Validity in RFC 5280. This value is unaffected when ValidityNotBefore is also specified. For example, if Validity is set to 20 days in the future, the certificate will expire 20 days from issuance time regardless of the ValidityNotBefore value. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-certificatevalidity.html#cfn-pcaconnectorad-template-certificatevalidity-validityperiod // ValidityPeriod interface{} `field:"required" json:"validityPeriod" yaml:"validityPeriod"` }
Information describing the end of the validity period of the certificate.
This parameter sets the “Not After” date for the certificate. Certificate validity is the period of time during which a certificate is valid. Validity can be expressed as an explicit date and time when the certificate expires, or as a span of time after issuance, stated in days, months, or years. For more information, see Validity in RFC 5280. This value is unaffected when ValidityNotBefore is also specified. For example, if Validity is set to 20 days in the future, the certificate will expire 20 days from issuance time regardless of the ValidityNotBefore value.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" certificateValidityProperty := &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }
type CfnTemplate_EnrollmentFlagsV2Property ¶
type CfnTemplate_EnrollmentFlagsV2Property struct { // Allow renewal using the same key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv2.html#cfn-pcaconnectorad-template-enrollmentflagsv2-enablekeyreuseonnttokenkeysetstoragefull // EnableKeyReuseOnNtTokenKeysetStorageFull interface{} `field:"optional" json:"enableKeyReuseOnNtTokenKeysetStorageFull" yaml:"enableKeyReuseOnNtTokenKeysetStorageFull"` // Include symmetric algorithms allowed by the subject. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv2.html#cfn-pcaconnectorad-template-enrollmentflagsv2-includesymmetricalgorithms // IncludeSymmetricAlgorithms interface{} `field:"optional" json:"includeSymmetricAlgorithms" yaml:"includeSymmetricAlgorithms"` // This flag instructs the CA to not include the security extension szOID_NTDS_CA_SECURITY_EXT (OID:1.3.6.1.4.1.311.25.2), as specified in [MS-WCCE] sections 2.2.2.7.7.4 and 3.2.2.6.2.1.4.5.9, in the issued certificate. This addresses a Windows Kerberos elevation-of-privilege vulnerability. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv2.html#cfn-pcaconnectorad-template-enrollmentflagsv2-nosecurityextension // NoSecurityExtension interface{} `field:"optional" json:"noSecurityExtension" yaml:"noSecurityExtension"` // Delete expired or revoked certificates instead of archiving them. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv2.html#cfn-pcaconnectorad-template-enrollmentflagsv2-removeinvalidcertificatefrompersonalstore // RemoveInvalidCertificateFromPersonalStore interface{} `field:"optional" json:"removeInvalidCertificateFromPersonalStore" yaml:"removeInvalidCertificateFromPersonalStore"` // Require user interaction when the subject is enrolled and the private key associated with the certificate is used. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv2.html#cfn-pcaconnectorad-template-enrollmentflagsv2-userinteractionrequired // UserInteractionRequired interface{} `field:"optional" json:"userInteractionRequired" yaml:"userInteractionRequired"` }
Template configurations for v2 template schema.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" enrollmentFlagsV2Property := &EnrollmentFlagsV2Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }
type CfnTemplate_EnrollmentFlagsV3Property ¶
type CfnTemplate_EnrollmentFlagsV3Property struct { // Allow renewal using the same key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv3.html#cfn-pcaconnectorad-template-enrollmentflagsv3-enablekeyreuseonnttokenkeysetstoragefull // EnableKeyReuseOnNtTokenKeysetStorageFull interface{} `field:"optional" json:"enableKeyReuseOnNtTokenKeysetStorageFull" yaml:"enableKeyReuseOnNtTokenKeysetStorageFull"` // Include symmetric algorithms allowed by the subject. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv3.html#cfn-pcaconnectorad-template-enrollmentflagsv3-includesymmetricalgorithms // IncludeSymmetricAlgorithms interface{} `field:"optional" json:"includeSymmetricAlgorithms" yaml:"includeSymmetricAlgorithms"` // This flag instructs the CA to not include the security extension szOID_NTDS_CA_SECURITY_EXT (OID:1.3.6.1.4.1.311.25.2), as specified in [MS-WCCE] sections 2.2.2.7.7.4 and 3.2.2.6.2.1.4.5.9, in the issued certificate. This addresses a Windows Kerberos elevation-of-privilege vulnerability. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv3.html#cfn-pcaconnectorad-template-enrollmentflagsv3-nosecurityextension // NoSecurityExtension interface{} `field:"optional" json:"noSecurityExtension" yaml:"noSecurityExtension"` // Delete expired or revoked certificates instead of archiving them. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv3.html#cfn-pcaconnectorad-template-enrollmentflagsv3-removeinvalidcertificatefrompersonalstore // RemoveInvalidCertificateFromPersonalStore interface{} `field:"optional" json:"removeInvalidCertificateFromPersonalStore" yaml:"removeInvalidCertificateFromPersonalStore"` // Require user interaction when the subject is enrolled and the private key associated with the certificate is used. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv3.html#cfn-pcaconnectorad-template-enrollmentflagsv3-userinteractionrequired // UserInteractionRequired interface{} `field:"optional" json:"userInteractionRequired" yaml:"userInteractionRequired"` }
Template configurations for v3 template schema.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" enrollmentFlagsV3Property := &EnrollmentFlagsV3Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }
type CfnTemplate_EnrollmentFlagsV4Property ¶
type CfnTemplate_EnrollmentFlagsV4Property struct { // Allow renewal using the same key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv4.html#cfn-pcaconnectorad-template-enrollmentflagsv4-enablekeyreuseonnttokenkeysetstoragefull // EnableKeyReuseOnNtTokenKeysetStorageFull interface{} `field:"optional" json:"enableKeyReuseOnNtTokenKeysetStorageFull" yaml:"enableKeyReuseOnNtTokenKeysetStorageFull"` // Include symmetric algorithms allowed by the subject. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv4.html#cfn-pcaconnectorad-template-enrollmentflagsv4-includesymmetricalgorithms // IncludeSymmetricAlgorithms interface{} `field:"optional" json:"includeSymmetricAlgorithms" yaml:"includeSymmetricAlgorithms"` // This flag instructs the CA to not include the security extension szOID_NTDS_CA_SECURITY_EXT (OID:1.3.6.1.4.1.311.25.2), as specified in [MS-WCCE] sections 2.2.2.7.7.4 and 3.2.2.6.2.1.4.5.9, in the issued certificate. This addresses a Windows Kerberos elevation-of-privilege vulnerability. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv4.html#cfn-pcaconnectorad-template-enrollmentflagsv4-nosecurityextension // NoSecurityExtension interface{} `field:"optional" json:"noSecurityExtension" yaml:"noSecurityExtension"` // Delete expired or revoked certificates instead of archiving them. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv4.html#cfn-pcaconnectorad-template-enrollmentflagsv4-removeinvalidcertificatefrompersonalstore // RemoveInvalidCertificateFromPersonalStore interface{} `field:"optional" json:"removeInvalidCertificateFromPersonalStore" yaml:"removeInvalidCertificateFromPersonalStore"` // Require user interaction when the subject is enrolled and the private key associated with the certificate is used. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-enrollmentflagsv4.html#cfn-pcaconnectorad-template-enrollmentflagsv4-userinteractionrequired // UserInteractionRequired interface{} `field:"optional" json:"userInteractionRequired" yaml:"userInteractionRequired"` }
Template configurations for v4 template schema.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" enrollmentFlagsV4Property := &EnrollmentFlagsV4Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }
type CfnTemplate_ExtensionsV2Property ¶
type CfnTemplate_ExtensionsV2Property struct { // The key usage extension defines the purpose (e.g., encipherment, signature, certificate signing) of the key contained in the certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-extensionsv2.html#cfn-pcaconnectorad-template-extensionsv2-keyusage // KeyUsage interface{} `field:"required" json:"keyUsage" yaml:"keyUsage"` // Application policies specify what the certificate is used for and its purpose. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-extensionsv2.html#cfn-pcaconnectorad-template-extensionsv2-applicationpolicies // ApplicationPolicies interface{} `field:"optional" json:"applicationPolicies" yaml:"applicationPolicies"` }
Certificate extensions for v2 template schema.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" extensionsV2Property := &ExtensionsV2Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }
type CfnTemplate_ExtensionsV3Property ¶
type CfnTemplate_ExtensionsV3Property struct { // The key usage extension defines the purpose (e.g., encipherment, signature, certificate signing) of the key contained in the certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-extensionsv3.html#cfn-pcaconnectorad-template-extensionsv3-keyusage // KeyUsage interface{} `field:"required" json:"keyUsage" yaml:"keyUsage"` // Application policies specify what the certificate is used for and its purpose. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-extensionsv3.html#cfn-pcaconnectorad-template-extensionsv3-applicationpolicies // ApplicationPolicies interface{} `field:"optional" json:"applicationPolicies" yaml:"applicationPolicies"` }
Certificate extensions for v3 template schema.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" extensionsV3Property := &ExtensionsV3Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }
type CfnTemplate_ExtensionsV4Property ¶
type CfnTemplate_ExtensionsV4Property struct { // The key usage extension defines the purpose (e.g., encipherment, signature) of the key contained in the certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-extensionsv4.html#cfn-pcaconnectorad-template-extensionsv4-keyusage // KeyUsage interface{} `field:"required" json:"keyUsage" yaml:"keyUsage"` // Application policies specify what the certificate is used for and its purpose. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-extensionsv4.html#cfn-pcaconnectorad-template-extensionsv4-applicationpolicies // ApplicationPolicies interface{} `field:"optional" json:"applicationPolicies" yaml:"applicationPolicies"` }
Certificate extensions for v4 template schema.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" extensionsV4Property := &ExtensionsV4Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }
type CfnTemplate_GeneralFlagsV2Property ¶
type CfnTemplate_GeneralFlagsV2Property struct { // Allows certificate issuance using autoenrollment. // // Set to TRUE to allow autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-generalflagsv2.html#cfn-pcaconnectorad-template-generalflagsv2-autoenrollment // AutoEnrollment interface{} `field:"optional" json:"autoEnrollment" yaml:"autoEnrollment"` // Defines if the template is for machines or users. // // Set to TRUE if the template is for machines. Set to FALSE if the template is for users. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-generalflagsv2.html#cfn-pcaconnectorad-template-generalflagsv2-machinetype // MachineType interface{} `field:"optional" json:"machineType" yaml:"machineType"` }
General flags for v2 template schema that defines if the template is for a machine or a user and if the template can be issued using autoenrollment.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" generalFlagsV2Property := &GeneralFlagsV2Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }
type CfnTemplate_GeneralFlagsV3Property ¶
type CfnTemplate_GeneralFlagsV3Property struct { // Allows certificate issuance using autoenrollment. // // Set to TRUE to allow autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-generalflagsv3.html#cfn-pcaconnectorad-template-generalflagsv3-autoenrollment // AutoEnrollment interface{} `field:"optional" json:"autoEnrollment" yaml:"autoEnrollment"` // Defines if the template is for machines or users. // // Set to TRUE if the template is for machines. Set to FALSE if the template is for users // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-generalflagsv3.html#cfn-pcaconnectorad-template-generalflagsv3-machinetype // MachineType interface{} `field:"optional" json:"machineType" yaml:"machineType"` }
General flags for v3 template schema that defines if the template is for a machine or a user and if the template can be issued using autoenrollment.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" generalFlagsV3Property := &GeneralFlagsV3Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }
type CfnTemplate_GeneralFlagsV4Property ¶
type CfnTemplate_GeneralFlagsV4Property struct { // Allows certificate issuance using autoenrollment. // // Set to TRUE to allow autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-generalflagsv4.html#cfn-pcaconnectorad-template-generalflagsv4-autoenrollment // AutoEnrollment interface{} `field:"optional" json:"autoEnrollment" yaml:"autoEnrollment"` // Defines if the template is for machines or users. // // Set to TRUE if the template is for machines. Set to FALSE if the template is for users // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-generalflagsv4.html#cfn-pcaconnectorad-template-generalflagsv4-machinetype // MachineType interface{} `field:"optional" json:"machineType" yaml:"machineType"` }
General flags for v4 template schema that defines if the template is for a machine or a user and if the template can be issued using autoenrollment.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" generalFlagsV4Property := &GeneralFlagsV4Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }
type CfnTemplate_KeyUsageFlagsProperty ¶
type CfnTemplate_KeyUsageFlagsProperty struct { // DataEncipherment is asserted when the subject public key is used for directly enciphering raw user data without the use of an intermediate symmetric cipher. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageflags.html#cfn-pcaconnectorad-template-keyusageflags-dataencipherment // DataEncipherment interface{} `field:"optional" json:"dataEncipherment" yaml:"dataEncipherment"` // The digitalSignature is asserted when the subject public key is used for verifying digital signatures. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageflags.html#cfn-pcaconnectorad-template-keyusageflags-digitalsignature // DigitalSignature interface{} `field:"optional" json:"digitalSignature" yaml:"digitalSignature"` // KeyAgreement is asserted when the subject public key is used for key agreement. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageflags.html#cfn-pcaconnectorad-template-keyusageflags-keyagreement // KeyAgreement interface{} `field:"optional" json:"keyAgreement" yaml:"keyAgreement"` // KeyEncipherment is asserted when the subject public key is used for enciphering private or secret keys, i.e., for key transport. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageflags.html#cfn-pcaconnectorad-template-keyusageflags-keyencipherment // KeyEncipherment interface{} `field:"optional" json:"keyEncipherment" yaml:"keyEncipherment"` // NonRepudiation is asserted when the subject public key is used to verify digital signatures. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageflags.html#cfn-pcaconnectorad-template-keyusageflags-nonrepudiation // NonRepudiation interface{} `field:"optional" json:"nonRepudiation" yaml:"nonRepudiation"` }
The key usage flags represent the purpose (e.g., encipherment, signature) of the key contained in the certificate.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" keyUsageFlagsProperty := &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }
type CfnTemplate_KeyUsageProperty ¶
type CfnTemplate_KeyUsageProperty struct { // The key usage flags represent the purpose (e.g., encipherment, signature) of the key contained in the certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusage.html#cfn-pcaconnectorad-template-keyusage-usageflags // UsageFlags interface{} `field:"required" json:"usageFlags" yaml:"usageFlags"` // Sets the key usage extension to critical. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusage.html#cfn-pcaconnectorad-template-keyusage-critical // Critical interface{} `field:"optional" json:"critical" yaml:"critical"` }
The key usage extension defines the purpose (e.g., encipherment, signature) of the key contained in the certificate.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" keyUsageProperty := &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }
type CfnTemplate_KeyUsagePropertyFlagsProperty ¶
type CfnTemplate_KeyUsagePropertyFlagsProperty struct { // Allows key for encryption and decryption. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusagepropertyflags.html#cfn-pcaconnectorad-template-keyusagepropertyflags-decrypt // Decrypt interface{} `field:"optional" json:"decrypt" yaml:"decrypt"` // Allows key exchange without encryption. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusagepropertyflags.html#cfn-pcaconnectorad-template-keyusagepropertyflags-keyagreement // KeyAgreement interface{} `field:"optional" json:"keyAgreement" yaml:"keyAgreement"` // Allow key use for digital signature. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusagepropertyflags.html#cfn-pcaconnectorad-template-keyusagepropertyflags-sign // Sign interface{} `field:"optional" json:"sign" yaml:"sign"` }
Specifies key usage.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" keyUsagePropertyFlagsProperty := &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }
type CfnTemplate_KeyUsagePropertyProperty ¶
type CfnTemplate_KeyUsagePropertyProperty struct { // You can specify key usage for encryption, key agreement, and signature. // // You can use property flags or property type but not both. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageproperty.html#cfn-pcaconnectorad-template-keyusageproperty-propertyflags // PropertyFlags interface{} `field:"optional" json:"propertyFlags" yaml:"propertyFlags"` // You can specify all key usages using property type ALL. // // You can use property type or property flags but not both. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-keyusageproperty.html#cfn-pcaconnectorad-template-keyusageproperty-propertytype // PropertyType *string `field:"optional" json:"propertyType" yaml:"propertyType"` }
The key usage property defines the purpose of the private key contained in the certificate.
You can specify specific purposes using property flags or all by using property type ALL.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" keyUsagePropertyProperty := &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }
type CfnTemplate_PrivateKeyAttributesV2Property ¶
type CfnTemplate_PrivateKeyAttributesV2Property struct { // Defines the purpose of the private key. // // Set it to "KEY_EXCHANGE" or "SIGNATURE" value. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv2.html#cfn-pcaconnectorad-template-privatekeyattributesv2-keyspec // KeySpec *string `field:"required" json:"keySpec" yaml:"keySpec"` // Set the minimum key length of the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv2.html#cfn-pcaconnectorad-template-privatekeyattributesv2-minimalkeylength // MinimalKeyLength *float64 `field:"required" json:"minimalKeyLength" yaml:"minimalKeyLength"` // Defines the cryptographic providers used to generate the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv2.html#cfn-pcaconnectorad-template-privatekeyattributesv2-cryptoproviders // CryptoProviders *[]*string `field:"optional" json:"cryptoProviders" yaml:"cryptoProviders"` }
Defines the attributes of the private key.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" privateKeyAttributesV2Property := &PrivateKeyAttributesV2Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }
type CfnTemplate_PrivateKeyAttributesV3Property ¶
type CfnTemplate_PrivateKeyAttributesV3Property struct { // Defines the algorithm used to generate the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv3.html#cfn-pcaconnectorad-template-privatekeyattributesv3-algorithm // Algorithm *string `field:"required" json:"algorithm" yaml:"algorithm"` // Defines the purpose of the private key. // // Set it to "KEY_EXCHANGE" or "SIGNATURE" value. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv3.html#cfn-pcaconnectorad-template-privatekeyattributesv3-keyspec // KeySpec *string `field:"required" json:"keySpec" yaml:"keySpec"` // The key usage property defines the purpose of the private key contained in the certificate. // // You can specify specific purposes using property flags or all by using property type ALL. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv3.html#cfn-pcaconnectorad-template-privatekeyattributesv3-keyusageproperty // KeyUsageProperty interface{} `field:"required" json:"keyUsageProperty" yaml:"keyUsageProperty"` // Set the minimum key length of the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv3.html#cfn-pcaconnectorad-template-privatekeyattributesv3-minimalkeylength // MinimalKeyLength *float64 `field:"required" json:"minimalKeyLength" yaml:"minimalKeyLength"` // Defines the cryptographic providers used to generate the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv3.html#cfn-pcaconnectorad-template-privatekeyattributesv3-cryptoproviders // CryptoProviders *[]*string `field:"optional" json:"cryptoProviders" yaml:"cryptoProviders"` }
Defines the attributes of the private key.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" privateKeyAttributesV3Property := &PrivateKeyAttributesV3Property{ Algorithm: jsii.String("algorithm"), KeySpec: jsii.String("keySpec"), KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }
type CfnTemplate_PrivateKeyAttributesV4Property ¶
type CfnTemplate_PrivateKeyAttributesV4Property struct { // Defines the purpose of the private key. // // Set it to "KEY_EXCHANGE" or "SIGNATURE" value. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv4.html#cfn-pcaconnectorad-template-privatekeyattributesv4-keyspec // KeySpec *string `field:"required" json:"keySpec" yaml:"keySpec"` // Set the minimum key length of the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv4.html#cfn-pcaconnectorad-template-privatekeyattributesv4-minimalkeylength // MinimalKeyLength *float64 `field:"required" json:"minimalKeyLength" yaml:"minimalKeyLength"` // Defines the algorithm used to generate the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv4.html#cfn-pcaconnectorad-template-privatekeyattributesv4-algorithm // Algorithm *string `field:"optional" json:"algorithm" yaml:"algorithm"` // Defines the cryptographic providers used to generate the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv4.html#cfn-pcaconnectorad-template-privatekeyattributesv4-cryptoproviders // CryptoProviders *[]*string `field:"optional" json:"cryptoProviders" yaml:"cryptoProviders"` // The key usage property defines the purpose of the private key contained in the certificate. // // You can specify specific purposes using property flags or all by using property type ALL. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyattributesv4.html#cfn-pcaconnectorad-template-privatekeyattributesv4-keyusageproperty // KeyUsageProperty interface{} `field:"optional" json:"keyUsageProperty" yaml:"keyUsageProperty"` }
Defines the attributes of the private key.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" privateKeyAttributesV4Property := &PrivateKeyAttributesV4Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional Algorithm: jsii.String("algorithm"), CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, }
type CfnTemplate_PrivateKeyFlagsV2Property ¶
type CfnTemplate_PrivateKeyFlagsV2Property struct { // Defines the minimum client compatibility. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv2.html#cfn-pcaconnectorad-template-privatekeyflagsv2-clientversion // ClientVersion *string `field:"required" json:"clientVersion" yaml:"clientVersion"` // Allows the private key to be exported. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv2.html#cfn-pcaconnectorad-template-privatekeyflagsv2-exportablekey // ExportableKey interface{} `field:"optional" json:"exportableKey" yaml:"exportableKey"` // Require user input when using the private key for enrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv2.html#cfn-pcaconnectorad-template-privatekeyflagsv2-strongkeyprotectionrequired // StrongKeyProtectionRequired interface{} `field:"optional" json:"strongKeyProtectionRequired" yaml:"strongKeyProtectionRequired"` }
Private key flags for v2 templates specify the client compatibility, if the private key can be exported, and if user input is required when using a private key.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" privateKeyFlagsV2Property := &PrivateKeyFlagsV2Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }
type CfnTemplate_PrivateKeyFlagsV3Property ¶
type CfnTemplate_PrivateKeyFlagsV3Property struct { // Defines the minimum client compatibility. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv3.html#cfn-pcaconnectorad-template-privatekeyflagsv3-clientversion // ClientVersion *string `field:"required" json:"clientVersion" yaml:"clientVersion"` // Allows the private key to be exported. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv3.html#cfn-pcaconnectorad-template-privatekeyflagsv3-exportablekey // ExportableKey interface{} `field:"optional" json:"exportableKey" yaml:"exportableKey"` // Reguires the PKCS #1 v2.1 signature format for certificates. You should verify that your CA, objects, and applications can accept this signature format. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv3.html#cfn-pcaconnectorad-template-privatekeyflagsv3-requirealternatesignaturealgorithm // RequireAlternateSignatureAlgorithm interface{} `field:"optional" json:"requireAlternateSignatureAlgorithm" yaml:"requireAlternateSignatureAlgorithm"` // Requirer user input when using the private key for enrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv3.html#cfn-pcaconnectorad-template-privatekeyflagsv3-strongkeyprotectionrequired // StrongKeyProtectionRequired interface{} `field:"optional" json:"strongKeyProtectionRequired" yaml:"strongKeyProtectionRequired"` }
Private key flags for v3 templates specify the client compatibility, if the private key can be exported, if user input is required when using a private key, and if an alternate signature algorithm should be used.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" privateKeyFlagsV3Property := &PrivateKeyFlagsV3Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }
type CfnTemplate_PrivateKeyFlagsV4Property ¶
type CfnTemplate_PrivateKeyFlagsV4Property struct { // Defines the minimum client compatibility. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv4.html#cfn-pcaconnectorad-template-privatekeyflagsv4-clientversion // ClientVersion *string `field:"required" json:"clientVersion" yaml:"clientVersion"` // Allows the private key to be exported. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv4.html#cfn-pcaconnectorad-template-privatekeyflagsv4-exportablekey // ExportableKey interface{} `field:"optional" json:"exportableKey" yaml:"exportableKey"` // Requires the PKCS #1 v2.1 signature format for certificates. You should verify that your CA, objects, and applications can accept this signature format. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv4.html#cfn-pcaconnectorad-template-privatekeyflagsv4-requirealternatesignaturealgorithm // RequireAlternateSignatureAlgorithm interface{} `field:"optional" json:"requireAlternateSignatureAlgorithm" yaml:"requireAlternateSignatureAlgorithm"` // Renew certificate using the same private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv4.html#cfn-pcaconnectorad-template-privatekeyflagsv4-requiresamekeyrenewal // RequireSameKeyRenewal interface{} `field:"optional" json:"requireSameKeyRenewal" yaml:"requireSameKeyRenewal"` // Require user input when using the private key for enrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv4.html#cfn-pcaconnectorad-template-privatekeyflagsv4-strongkeyprotectionrequired // StrongKeyProtectionRequired interface{} `field:"optional" json:"strongKeyProtectionRequired" yaml:"strongKeyProtectionRequired"` // Specifies the cryptographic service provider category used to generate private keys. // // Set to TRUE to use Legacy Cryptographic Service Providers and FALSE to use Key Storage Providers. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-privatekeyflagsv4.html#cfn-pcaconnectorad-template-privatekeyflagsv4-uselegacyprovider // UseLegacyProvider interface{} `field:"optional" json:"useLegacyProvider" yaml:"useLegacyProvider"` }
Private key flags for v4 templates specify the client compatibility, if the private key can be exported, if user input is required when using a private key, if an alternate signature algorithm should be used, and if certificates are renewed using the same private key.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" privateKeyFlagsV4Property := &PrivateKeyFlagsV4Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), RequireSameKeyRenewal: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), UseLegacyProvider: jsii.Boolean(false), }
type CfnTemplate_SubjectNameFlagsV2Property ¶
type CfnTemplate_SubjectNameFlagsV2Property struct { // Include the common name in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-requirecommonname // RequireCommonName interface{} `field:"optional" json:"requireCommonName" yaml:"requireCommonName"` // Include the directory path in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-requiredirectorypath // RequireDirectoryPath interface{} `field:"optional" json:"requireDirectoryPath" yaml:"requireDirectoryPath"` // Include the DNS as common name in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-requirednsascn // RequireDnsAsCn interface{} `field:"optional" json:"requireDnsAsCn" yaml:"requireDnsAsCn"` // Include the subject's email in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-requireemail // RequireEmail interface{} `field:"optional" json:"requireEmail" yaml:"requireEmail"` // Include the globally unique identifier (GUID) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-sanrequiredirectoryguid // SanRequireDirectoryGuid interface{} `field:"optional" json:"sanRequireDirectoryGuid" yaml:"sanRequireDirectoryGuid"` // Include the DNS in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-sanrequiredns // SanRequireDns interface{} `field:"optional" json:"sanRequireDns" yaml:"sanRequireDns"` // Include the domain DNS in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-sanrequiredomaindns // SanRequireDomainDns interface{} `field:"optional" json:"sanRequireDomainDns" yaml:"sanRequireDomainDns"` // Include the subject's email in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-sanrequireemail // SanRequireEmail interface{} `field:"optional" json:"sanRequireEmail" yaml:"sanRequireEmail"` // Include the service principal name (SPN) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-sanrequirespn // SanRequireSpn interface{} `field:"optional" json:"sanRequireSpn" yaml:"sanRequireSpn"` // Include the user principal name (UPN) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv2.html#cfn-pcaconnectorad-template-subjectnameflagsv2-sanrequireupn // SanRequireUpn interface{} `field:"optional" json:"sanRequireUpn" yaml:"sanRequireUpn"` }
Information to include in the subject name and alternate subject name of the certificate.
The subject name can be common name, directory path, DNS as common name, or left blank. You can optionally include email to the subject name for user templates. If you leave the subject name blank then you must set a subject alternate name. The subject alternate name (SAN) can include globally unique identifier (GUID), DNS, domain DNS, email, service principal name (SPN), and user principal name (UPN). You can leave the SAN blank. If you leave the SAN blank, then you must set a subject name.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" subjectNameFlagsV2Property := &SubjectNameFlagsV2Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }
type CfnTemplate_SubjectNameFlagsV3Property ¶
type CfnTemplate_SubjectNameFlagsV3Property struct { // Include the common name in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-requirecommonname // RequireCommonName interface{} `field:"optional" json:"requireCommonName" yaml:"requireCommonName"` // Include the directory path in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-requiredirectorypath // RequireDirectoryPath interface{} `field:"optional" json:"requireDirectoryPath" yaml:"requireDirectoryPath"` // Include the DNS as common name in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-requirednsascn // RequireDnsAsCn interface{} `field:"optional" json:"requireDnsAsCn" yaml:"requireDnsAsCn"` // Include the subject's email in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-requireemail // RequireEmail interface{} `field:"optional" json:"requireEmail" yaml:"requireEmail"` // Include the globally unique identifier (GUID) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-sanrequiredirectoryguid // SanRequireDirectoryGuid interface{} `field:"optional" json:"sanRequireDirectoryGuid" yaml:"sanRequireDirectoryGuid"` // Include the DNS in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-sanrequiredns // SanRequireDns interface{} `field:"optional" json:"sanRequireDns" yaml:"sanRequireDns"` // Include the domain DNS in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-sanrequiredomaindns // SanRequireDomainDns interface{} `field:"optional" json:"sanRequireDomainDns" yaml:"sanRequireDomainDns"` // Include the subject's email in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-sanrequireemail // SanRequireEmail interface{} `field:"optional" json:"sanRequireEmail" yaml:"sanRequireEmail"` // Include the service principal name (SPN) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-sanrequirespn // SanRequireSpn interface{} `field:"optional" json:"sanRequireSpn" yaml:"sanRequireSpn"` // Include the user principal name (UPN) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv3.html#cfn-pcaconnectorad-template-subjectnameflagsv3-sanrequireupn // SanRequireUpn interface{} `field:"optional" json:"sanRequireUpn" yaml:"sanRequireUpn"` }
Information to include in the subject name and alternate subject name of the certificate.
The subject name can be common name, directory path, DNS as common name, or left blank. You can optionally include email to the subject name for user templates. If you leave the subject name blank then you must set a subject alternate name. The subject alternate name (SAN) can include globally unique identifier (GUID), DNS, domain DNS, email, service principal name (SPN), and user principal name (UPN). You can leave the SAN blank. If you leave the SAN blank, then you must set a subject name.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" subjectNameFlagsV3Property := &SubjectNameFlagsV3Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }
type CfnTemplate_SubjectNameFlagsV4Property ¶
type CfnTemplate_SubjectNameFlagsV4Property struct { // Include the common name in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-requirecommonname // RequireCommonName interface{} `field:"optional" json:"requireCommonName" yaml:"requireCommonName"` // Include the directory path in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-requiredirectorypath // RequireDirectoryPath interface{} `field:"optional" json:"requireDirectoryPath" yaml:"requireDirectoryPath"` // Include the DNS as common name in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-requirednsascn // RequireDnsAsCn interface{} `field:"optional" json:"requireDnsAsCn" yaml:"requireDnsAsCn"` // Include the subject's email in the subject name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-requireemail // RequireEmail interface{} `field:"optional" json:"requireEmail" yaml:"requireEmail"` // Include the globally unique identifier (GUID) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-sanrequiredirectoryguid // SanRequireDirectoryGuid interface{} `field:"optional" json:"sanRequireDirectoryGuid" yaml:"sanRequireDirectoryGuid"` // Include the DNS in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-sanrequiredns // SanRequireDns interface{} `field:"optional" json:"sanRequireDns" yaml:"sanRequireDns"` // Include the domain DNS in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-sanrequiredomaindns // SanRequireDomainDns interface{} `field:"optional" json:"sanRequireDomainDns" yaml:"sanRequireDomainDns"` // Include the subject's email in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-sanrequireemail // SanRequireEmail interface{} `field:"optional" json:"sanRequireEmail" yaml:"sanRequireEmail"` // Include the service principal name (SPN) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-sanrequirespn // SanRequireSpn interface{} `field:"optional" json:"sanRequireSpn" yaml:"sanRequireSpn"` // Include the user principal name (UPN) in the subject alternate name. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-subjectnameflagsv4.html#cfn-pcaconnectorad-template-subjectnameflagsv4-sanrequireupn // SanRequireUpn interface{} `field:"optional" json:"sanRequireUpn" yaml:"sanRequireUpn"` }
Information to include in the subject name and alternate subject name of the certificate.
The subject name can be common name, directory path, DNS as common name, or left blank. You can optionally include email to the subject name for user templates. If you leave the subject name blank then you must set a subject alternate name. The subject alternate name (SAN) can include globally unique identifier (GUID), DNS, domain DNS, email, service principal name (SPN), and user principal name (UPN). You can leave the SAN blank. If you leave the SAN blank, then you must set a subject name.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" subjectNameFlagsV4Property := &SubjectNameFlagsV4Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }
type CfnTemplate_TemplateDefinitionProperty ¶
type CfnTemplate_TemplateDefinitionProperty struct { // Template configuration to define the information included in certificates. // // Define certificate validity and renewal periods, certificate request handling and enrollment options, key usage extensions, application policies, and cryptography settings. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatedefinition.html#cfn-pcaconnectorad-template-templatedefinition-templatev2 // TemplateV2 interface{} `field:"optional" json:"templateV2" yaml:"templateV2"` // Template configuration to define the information included in certificates. // // Define certificate validity and renewal periods, certificate request handling and enrollment options, key usage extensions, application policies, and cryptography settings. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatedefinition.html#cfn-pcaconnectorad-template-templatedefinition-templatev3 // TemplateV3 interface{} `field:"optional" json:"templateV3" yaml:"templateV3"` // Template configuration to define the information included in certificates. // // Define certificate validity and renewal periods, certificate request handling and enrollment options, key usage extensions, application policies, and cryptography settings. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatedefinition.html#cfn-pcaconnectorad-template-templatedefinition-templatev4 // TemplateV4 interface{} `field:"optional" json:"templateV4" yaml:"templateV4"` }
Template configuration to define the information included in certificates.
Define certificate validity and renewal periods, certificate request handling and enrollment options, key usage extensions, application policies, and cryptography settings.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" templateDefinitionProperty := &TemplateDefinitionProperty{ TemplateV2: &TemplateV2Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV2Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV2Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV2Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV2Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV2Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV2Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, TemplateV3: &TemplateV3Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV3Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV3Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV3Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, HashAlgorithm: jsii.String("hashAlgorithm"), PrivateKeyAttributes: &PrivateKeyAttributesV3Property{ Algorithm: jsii.String("algorithm"), KeySpec: jsii.String("keySpec"), KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV3Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV3Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, TemplateV4: &TemplateV4Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV4Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV4Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV4Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV4Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional Algorithm: jsii.String("algorithm"), CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV4Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), RequireSameKeyRenewal: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), UseLegacyProvider: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV4Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional HashAlgorithm: jsii.String("hashAlgorithm"), SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }, }
type CfnTemplate_TemplateV2Property ¶
type CfnTemplate_TemplateV2Property struct { // Certificate validity describes the validity and renewal periods of a certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-certificatevalidity // CertificateValidity interface{} `field:"required" json:"certificateValidity" yaml:"certificateValidity"` // Enrollment flags describe the enrollment settings for certificates such as using the existing private key and deleting expired or revoked certificates. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-enrollmentflags // EnrollmentFlags interface{} `field:"required" json:"enrollmentFlags" yaml:"enrollmentFlags"` // Extensions describe the key usage extensions and application policies for a template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-extensions // Extensions interface{} `field:"required" json:"extensions" yaml:"extensions"` // General flags describe whether the template is used for computers or users and if the template can be used with autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-generalflags // GeneralFlags interface{} `field:"required" json:"generalFlags" yaml:"generalFlags"` // Private key attributes allow you to specify the minimal key length, key spec, and cryptographic providers for the private key of a certificate for v2 templates. // // V2 templates allow you to use Legacy Cryptographic Service Providers. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-privatekeyattributes // PrivateKeyAttributes interface{} `field:"required" json:"privateKeyAttributes" yaml:"privateKeyAttributes"` // Private key flags for v2 templates specify the client compatibility, if the private key can be exported, and if user input is required when using a private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-privatekeyflags // PrivateKeyFlags interface{} `field:"required" json:"privateKeyFlags" yaml:"privateKeyFlags"` // Subject name flags describe the subject name and subject alternate name that is included in a certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-subjectnameflags // SubjectNameFlags interface{} `field:"required" json:"subjectNameFlags" yaml:"subjectNameFlags"` // List of templates in Active Directory that are superseded by this template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev2.html#cfn-pcaconnectorad-template-templatev2-supersededtemplates // SupersededTemplates *[]*string `field:"optional" json:"supersededTemplates" yaml:"supersededTemplates"` }
v2 template schema that uses Legacy Cryptographic Providers.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" templateV2Property := &TemplateV2Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV2Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV2Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV2Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV2Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV2Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV2Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }
type CfnTemplate_TemplateV3Property ¶
type CfnTemplate_TemplateV3Property struct { // Certificate validity describes the validity and renewal periods of a certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-certificatevalidity // CertificateValidity interface{} `field:"required" json:"certificateValidity" yaml:"certificateValidity"` // Enrollment flags describe the enrollment settings for certificates such as using the existing private key and deleting expired or revoked certificates. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-enrollmentflags // EnrollmentFlags interface{} `field:"required" json:"enrollmentFlags" yaml:"enrollmentFlags"` // Extensions describe the key usage extensions and application policies for a template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-extensions // Extensions interface{} `field:"required" json:"extensions" yaml:"extensions"` // General flags describe whether the template is used for computers or users and if the template can be used with autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-generalflags // GeneralFlags interface{} `field:"required" json:"generalFlags" yaml:"generalFlags"` // Specifies the hash algorithm used to hash the private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-hashalgorithm // HashAlgorithm *string `field:"required" json:"hashAlgorithm" yaml:"hashAlgorithm"` // Private key attributes allow you to specify the algorithm, minimal key length, key spec, key usage, and cryptographic providers for the private key of a certificate for v3 templates. // // V3 templates allow you to use Key Storage Providers. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-privatekeyattributes // PrivateKeyAttributes interface{} `field:"required" json:"privateKeyAttributes" yaml:"privateKeyAttributes"` // Private key flags for v3 templates specify the client compatibility, if the private key can be exported, if user input is required when using a private key, and if an alternate signature algorithm should be used. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-privatekeyflags // PrivateKeyFlags interface{} `field:"required" json:"privateKeyFlags" yaml:"privateKeyFlags"` // Subject name flags describe the subject name and subject alternate name that is included in a certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-subjectnameflags // SubjectNameFlags interface{} `field:"required" json:"subjectNameFlags" yaml:"subjectNameFlags"` // List of templates in Active Directory that are superseded by this template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev3.html#cfn-pcaconnectorad-template-templatev3-supersededtemplates // SupersededTemplates *[]*string `field:"optional" json:"supersededTemplates" yaml:"supersededTemplates"` }
v3 template schema that uses Key Storage Providers.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" templateV3Property := &TemplateV3Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV3Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV3Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV3Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, HashAlgorithm: jsii.String("hashAlgorithm"), PrivateKeyAttributes: &PrivateKeyAttributesV3Property{ Algorithm: jsii.String("algorithm"), KeySpec: jsii.String("keySpec"), KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, MinimalKeyLength: jsii.Number(123), // the properties below are optional CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV3Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV3Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }
type CfnTemplate_TemplateV4Property ¶
type CfnTemplate_TemplateV4Property struct { // Certificate validity describes the validity and renewal periods of a certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-certificatevalidity // CertificateValidity interface{} `field:"required" json:"certificateValidity" yaml:"certificateValidity"` // Enrollment flags describe the enrollment settings for certificates using the existing private key and deleting expired or revoked certificates. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-enrollmentflags // EnrollmentFlags interface{} `field:"required" json:"enrollmentFlags" yaml:"enrollmentFlags"` // Extensions describe the key usage extensions and application policies for a template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-extensions // Extensions interface{} `field:"required" json:"extensions" yaml:"extensions"` // General flags describe whether the template is used for computers or users and if the template can be used with autoenrollment. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-generalflags // GeneralFlags interface{} `field:"required" json:"generalFlags" yaml:"generalFlags"` // Private key attributes allow you to specify the minimal key length, key spec, key usage, and cryptographic providers for the private key of a certificate for v4 templates. // // V4 templates allow you to use either Key Storage Providers or Legacy Cryptographic Service Providers. You specify the cryptography provider category in private key flags. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-privatekeyattributes // PrivateKeyAttributes interface{} `field:"required" json:"privateKeyAttributes" yaml:"privateKeyAttributes"` // Private key flags for v4 templates specify the client compatibility, if the private key can be exported, if user input is required when using a private key, if an alternate signature algorithm should be used, and if certificates are renewed using the same private key. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-privatekeyflags // PrivateKeyFlags interface{} `field:"required" json:"privateKeyFlags" yaml:"privateKeyFlags"` // Subject name flags describe the subject name and subject alternate name that is included in a certificate. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-subjectnameflags // SubjectNameFlags interface{} `field:"required" json:"subjectNameFlags" yaml:"subjectNameFlags"` // Specifies the hash algorithm used to hash the private key. // // Hash algorithm can only be specified when using Key Storage Providers. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-hashalgorithm // HashAlgorithm *string `field:"optional" json:"hashAlgorithm" yaml:"hashAlgorithm"` // List of templates in Active Directory that are superseded by this template. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-templatev4.html#cfn-pcaconnectorad-template-templatev4-supersededtemplates // SupersededTemplates *[]*string `field:"optional" json:"supersededTemplates" yaml:"supersededTemplates"` }
v4 template schema that can use either Legacy Cryptographic Providers or Key Storage Providers.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" templateV4Property := &TemplateV4Property{ CertificateValidity: &CertificateValidityProperty{ RenewalPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, ValidityPeriod: &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }, }, EnrollmentFlags: &EnrollmentFlagsV4Property{ EnableKeyReuseOnNtTokenKeysetStorageFull: jsii.Boolean(false), IncludeSymmetricAlgorithms: jsii.Boolean(false), NoSecurityExtension: jsii.Boolean(false), RemoveInvalidCertificateFromPersonalStore: jsii.Boolean(false), UserInteractionRequired: jsii.Boolean(false), }, Extensions: &ExtensionsV4Property{ KeyUsage: &KeyUsageProperty{ UsageFlags: &KeyUsageFlagsProperty{ DataEncipherment: jsii.Boolean(false), DigitalSignature: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), KeyEncipherment: jsii.Boolean(false), NonRepudiation: jsii.Boolean(false), }, // the properties below are optional Critical: jsii.Boolean(false), }, // the properties below are optional ApplicationPolicies: &ApplicationPoliciesProperty{ Policies: []interface{}{ &ApplicationPolicyProperty{ PolicyObjectIdentifier: jsii.String("policyObjectIdentifier"), PolicyType: jsii.String("policyType"), }, }, // the properties below are optional Critical: jsii.Boolean(false), }, }, GeneralFlags: &GeneralFlagsV4Property{ AutoEnrollment: jsii.Boolean(false), MachineType: jsii.Boolean(false), }, PrivateKeyAttributes: &PrivateKeyAttributesV4Property{ KeySpec: jsii.String("keySpec"), MinimalKeyLength: jsii.Number(123), // the properties below are optional Algorithm: jsii.String("algorithm"), CryptoProviders: []*string{ jsii.String("cryptoProviders"), }, KeyUsageProperty: &KeyUsagePropertyProperty{ PropertyFlags: &KeyUsagePropertyFlagsProperty{ Decrypt: jsii.Boolean(false), KeyAgreement: jsii.Boolean(false), Sign: jsii.Boolean(false), }, PropertyType: jsii.String("propertyType"), }, }, PrivateKeyFlags: &PrivateKeyFlagsV4Property{ ClientVersion: jsii.String("clientVersion"), // the properties below are optional ExportableKey: jsii.Boolean(false), RequireAlternateSignatureAlgorithm: jsii.Boolean(false), RequireSameKeyRenewal: jsii.Boolean(false), StrongKeyProtectionRequired: jsii.Boolean(false), UseLegacyProvider: jsii.Boolean(false), }, SubjectNameFlags: &SubjectNameFlagsV4Property{ RequireCommonName: jsii.Boolean(false), RequireDirectoryPath: jsii.Boolean(false), RequireDnsAsCn: jsii.Boolean(false), RequireEmail: jsii.Boolean(false), SanRequireDirectoryGuid: jsii.Boolean(false), SanRequireDns: jsii.Boolean(false), SanRequireDomainDns: jsii.Boolean(false), SanRequireEmail: jsii.Boolean(false), SanRequireSpn: jsii.Boolean(false), SanRequireUpn: jsii.Boolean(false), }, // the properties below are optional HashAlgorithm: jsii.String("hashAlgorithm"), SupersededTemplates: []*string{ jsii.String("supersededTemplates"), }, }
type CfnTemplate_ValidityPeriodProperty ¶
type CfnTemplate_ValidityPeriodProperty struct { // The numeric value for the validity period. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-validityperiod.html#cfn-pcaconnectorad-template-validityperiod-period // Period *float64 `field:"required" json:"period" yaml:"period"` // The unit of time. // // You can select hours, days, weeks, months, and years. // See: http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-pcaconnectorad-template-validityperiod.html#cfn-pcaconnectorad-template-validityperiod-periodtype // PeriodType *string `field:"required" json:"periodType" yaml:"periodType"` }
Information describing the end of the validity period of the certificate.
This parameter sets the “Not After” date for the certificate. Certificate validity is the period of time during which a certificate is valid. Validity can be expressed as an explicit date and time when the certificate expires, or as a span of time after issuance, stated in hours, days, months, or years. For more information, see Validity in RFC 5280. This value is unaffected when ValidityNotBefore is also specified. For example, if Validity is set to 20 days in the future, the certificate will expire 20 days from issuance time regardless of the ValidityNotBefore value.
Example:
// The code below shows an example of how to instantiate this type. // The values are placeholders you should change. import "github.com/aws/aws-cdk-go/awscdk" validityPeriodProperty := &ValidityPeriodProperty{ Period: jsii.Number(123), PeriodType: jsii.String("periodType"), }
Source Files ¶
- CfnConnector.go
- CfnConnectorProps.go
- CfnConnector_VpcInformationProperty.go
- CfnConnector__checks.go
- CfnDirectoryRegistration.go
- CfnDirectoryRegistrationProps.go
- CfnDirectoryRegistration__checks.go
- CfnServicePrincipalName.go
- CfnServicePrincipalNameProps.go
- CfnServicePrincipalName__checks.go
- CfnTemplate.go
- CfnTemplateGroupAccessControlEntry.go
- CfnTemplateGroupAccessControlEntryProps.go
- CfnTemplateGroupAccessControlEntry_AccessRightsProperty.go
- CfnTemplateGroupAccessControlEntry__checks.go
- CfnTemplateProps.go
- CfnTemplate_ApplicationPoliciesProperty.go
- CfnTemplate_ApplicationPolicyProperty.go
- CfnTemplate_CertificateValidityProperty.go
- CfnTemplate_EnrollmentFlagsV2Property.go
- CfnTemplate_EnrollmentFlagsV3Property.go
- CfnTemplate_EnrollmentFlagsV4Property.go
- CfnTemplate_ExtensionsV2Property.go
- CfnTemplate_ExtensionsV3Property.go
- CfnTemplate_ExtensionsV4Property.go
- CfnTemplate_GeneralFlagsV2Property.go
- CfnTemplate_GeneralFlagsV3Property.go
- CfnTemplate_GeneralFlagsV4Property.go
- CfnTemplate_KeyUsageFlagsProperty.go
- CfnTemplate_KeyUsageProperty.go
- CfnTemplate_KeyUsagePropertyFlagsProperty.go
- CfnTemplate_KeyUsagePropertyProperty.go
- CfnTemplate_PrivateKeyAttributesV2Property.go
- CfnTemplate_PrivateKeyAttributesV3Property.go
- CfnTemplate_PrivateKeyAttributesV4Property.go
- CfnTemplate_PrivateKeyFlagsV2Property.go
- CfnTemplate_PrivateKeyFlagsV3Property.go
- CfnTemplate_PrivateKeyFlagsV4Property.go
- CfnTemplate_SubjectNameFlagsV2Property.go
- CfnTemplate_SubjectNameFlagsV3Property.go
- CfnTemplate_SubjectNameFlagsV4Property.go
- CfnTemplate_TemplateDefinitionProperty.go
- CfnTemplate_TemplateV2Property.go
- CfnTemplate_TemplateV3Property.go
- CfnTemplate_TemplateV4Property.go
- CfnTemplate_ValidityPeriodProperty.go
- CfnTemplate__checks.go
- main.go