Questions around key credentials
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 18/100
- Tipo de issue
- Documentación
- Claridad
- Necesita aclaración
- Estado de actividad
- Estancado
- Stack tecnológico
- azure, powershell
- Área
- authentication, cloud, documentation, security
Línea de trabajo
Revisa los ejemplos de main.bicep enlazados y la documentación referenciada de Microsoft Learn y PowerShell. Compara los valores documentados de key, usage y type con el esquema y el comportamiento del script de implementación, incluido el modo en que se gestionan los datos de certificados de Key Vault. La tarea se considera terminada cuando se proporcionen respuestas autorizadas o se actualice la documentación pertinente para resolver estas preguntas.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
I have several questions around key credentials.
- in the example here https://github.com/microsoftgraph/msgraph-bicep-types/blob/main/quickstart-templates/application-serviceprincipal-create-client-resource/main.bicep the cert key is passed as secure value. If I understand correctly we are passing public key and later this public key is visible in plain text in the manifest of the app. If that is the case why it is needed to be passed as secret when everything later is visible in plain text?
- What are the available values for usage property? When you enter wrong value the API returns that Verify and Sign are acceptable values but in some of the Learn docs (https://docs.azure.cn/en-us/entra/identity/enterprise-apps/howto-saml-token-encryption?tabs=azure-portal) I have saw that there are other values that are acceptable Encrypt. Where we can get information on all acceptable values for this property. Additionally the doc here https://learn.microsoft.com/en-us/powershell/module/microsoft.entra/new-entraapplicationkeycredential?view=entra-powershell mentions that "for AsymmetricX509Cert the usage must be Verify and for X509CertAndPassword the usage must be Sign". Are there certain values that are acceptable for one type and others for another type.
- What are the available values for type property. The schema mentions Symmetric and AsymmetricX509Cert but doc https://learn.microsoft.com/en-us/powershell/module/microsoft.entra/new-entraapplicationkeycredential?view=entra-powershell mentions also X509CertAndPassword but it does not mention Symmetric. Can we get all acceptable values and their different purposes?
- Is it possible to get the value of Key Vault certificate without using PS script in deployment script. In this example here https://github.com/microsoftgraph/msgraph-bicep-types/blob/main/quickstart-templates/create-client-app-sp-with-kv-cert/main.bicep deployment script is used to get the value needed for key property. I would assume that we do not have the right Bicep functions to be able to get the correct format of the value. In such case shouldn't we have such functions available or may be in addition of the certificate object in the Key Vault we should have a secret object where we have extracted the correct value (with PS for example) from the certificate and we have stored it in it. That way we can use .getSecret() function instead of having to use deployment script? Note that the output of the deployment script is in plain text which connects to the first question.
May be some of my questions are dumb but that is due to my limited knowledge in Entra
- Lenguaje dominante
- TypeScript
- Estrellas
- 81
- Forks
- 15
- Merge medio
- 3 d 8 h
- PR fusionados (30 d)
- 7
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoftgraph/msgraph-bicep-types
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
microsoftgraph/msgraph-bicep-types#311 · 3 comentarios ·
-
enhancement new type
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
-
enhancement
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
microsoftgraph/msgraph-bicep-types#304 · 3 comentarios · 1 reacción ·
-
enhancement new type
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
microsoftgraph/msgraph-bicep-types#296 · 2 reacciones ·
-
Issue with servicePrincipals and appRoleAssignedTo in some Entra TenantsQuizá libre de nuevo @eketo-msft la tomó hace 259 días y no hay ningún pull request abierto. Abiertobug
microsoftgraph/msgraph-bicep-types#275 · 5 comentarios · 1 asignado ·
Todos los issues de microsoftgraph/msgraph-bicep-types
Issues similares
-
triage
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
mermaid-js/mermaid-live-editor#2053 ·
Los mantenedores suelen responder en 1 día
-
factory
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
jessepollak/home#1455 ·
Los mantenedores suelen responder en 1 día
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
lingdojo/kana-dojo#31227 · 1 comentario · 5 reacciones ·
Los mantenedores suelen responder en 1 día
-
mobile: device viewer shows dark status bar icons on its dark backdrop in light mode (Android)Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
appandflow/stim#1838 ·
Los mantenedores suelen responder en 1 día