Home
Prerequisites
Test cases
Diagrams
Glossary
About
▾
Product
All products
KubeVirt
OpenBao
Red Hat (all products)
Red Hat OpenShift
OpenShift Virtualization
Advanced Cluster Management
☀
☾
?
⌕
⌘K
Ctrl+K
Skip to content
☰
Browse contents
Home
›
Diagrams
›
OpenBao: PKI hierarchy
Format:
Markdown
Print / PDF
Export:
Full plan
All prerequisites
All test cases
🧭
Architecture & setup diagrams
KubeVirt: Setup order
KubeVirt: Single-NIC architecture
KubeVirt: Capability matrix
OpenBao: Setup order
OpenBao: HA architecture
OpenBao: Unseal flows
OpenBao: Multi-tenant isolation
OpenBao: Secret delivery
OpenBao: PKI hierarchy
PKI — CA HIERARCHY AND AUTOMATED ISSUANCE
Root CA — mount pki/
CN=example.com · TTL 87600h (10 y)
sign intermediates only — never leaf certs
signs CSR
Intermediate CA — mount pki_int/
TTL 43800h (5 y) · set-signed
does the day-to-day issuing ·
PKI-001
Role: example-dot-com
allowed_domains + allow_subdomains
max_ttl 720h — guard-rail for issuance
Leaf certificate
CN=myapp.example.com · TTL 24h
short-lived by design — rotation is normal
cert-manager (
PKI-002
/
UC-001
·
PRE-11
)
ClusterIssuer (Vault type)
server: https://openbao…:8200
k8s auth role: cert-manager
Certificate CR
myapp.example.com
renewBefore: …
TLS Secret: app-tls
tls.crt · tls.key · ca.crt
chain: leaf → intermediate → root
Route / pod TLS
consumes the Secret
picked up on renewal
issues + renews
sign via pki_int role
Cross-signing (
PKI-003
):
external corporate root CA signs the CSR of a second intermediate (mount
pki_cross/
) → OpenBao-issued certs are trusted by clients that only trust the company PKI.
Import needs Basic Constraints CA:TRUE — sign with the v3_intermediate_ca extension.
Search test plan
⌕
All
🔧
Prerequisites
📚
Glossary
🧭
Diagrams
🖥️
VM Basics
🌐
Networking
🔀
VLANs
🔌
Multus CNI
⚒️
MetalLB
☁️
Hosted Control Planes
💾
Storage
🔄
Migration
💾
Backup & Restore
🗺️
ACM Fleet Management
☸️
OpenShift Installation
🔓
Auto-Unseal Mechanisms
🔑
KV Secrets Engine
📜
PKI Certificates
🗄️
Database Secrets
🔐
Authentication Methods
🏗️
High Availability (Raft)
🔗
OpenShift Integration
🏢
Real-World Use Cases
⌕
⌘K
Ctrl+K
Type at least 2 characters to search
Keyboard shortcuts
P
Go to prerequisites
T
Go to test cases
G
Go to glossary
D
Go to diagrams
J
Next card
K
Previous card
Enter
Open / close focused card
/
Open search
⌘
Ctrl
K
Open search modal
?
Show shortcuts
Esc
Close panel / blur search
Close