Skip to content

Prerequisites to use vSSH CLI with Venafi SSH Protect

Atanas Chuchev edited this page May 25, 2022 · 2 revisions

Apache 2.0 License Community Supported Compatible with TPP 21.4+
To report a problem or share an idea, use Issues; and if you have a suggestion for fixing the issue, please include those details, too. Got questions or want to discuss something with our team? Join us on Slack!

Prerequisites to use vSSH CLI with Venafi SSH Protect

  1. A user account that has been granted to acquire an authentication tokens for WebSDK access with "ssh:manage" scope
  2. Properly configured SSH certificate issuance template in Venafi SSH Protect:
    • Issuance restrictions applied to the template compliant with the organizational policies
    • Permissions (View & Create) to the template set to allow only desired users and groups to use it
    • When you want to use vSSH CLI to get credentials for interactive SSH access (i.e., vssh login operation) you need to configure the template with the following:
      • The default values of all certificate fields are set to be automatically populated by Venafi SSH Protect
      • Allow API clients to receive issued certificates in response to their enrollment requests

Next steps