Skip to content

Fixes broken path when issuing PKI with specified issuer ref - #1312

Open
TheLonelyGhost wants to merge 1 commit into
hashicorp:mainfrom
TheLonelyGhost:fix/pki-issuer-ref-broken-path
Open

Fixes broken path when issuing PKI with specified issuer ref#1312
TheLonelyGhost wants to merge 1 commit into
hashicorp:mainfrom
TheLonelyGhost:fix/pki-issuer-ref-broken-path

Conversation

@TheLonelyGhost

@TheLonelyGhost TheLonelyGhost commented Jul 22, 2026

Copy link
Copy Markdown

VaultPKISecret fails to issue a cert when issuer ref is specified. This is because the controller renders an invalid path for the resulting HTTP request, pointing to a location that does not follow the Vault API's published specification. Vault Server replies with a commensurate error.

With issuer ref, this change fixes the path from pki/issuer/MyCA/MyRole -> pki/issuer/MyCA/issue/MyRole (note the added /issue/ segment)

Without issuer ref, the path remains unchanged: pki/issue/MyRole.

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

`pki/issuers/MyCA/MyRole` -> `pki/issuers/MyCA/issue/MyRole`
@TheLonelyGhost
TheLonelyGhost requested review from a team as code owners July 22, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant