const ONLY_YUBIHSM2_MOCKHSM_ADMIN_SYSTEMD_CREDS_NON_ADMIN_PLAINTEXT: &[u8] = b"system:\n iteration: 1\n admin_secret_handling: systemd-creds\n non_admin_secret_handling: plaintext\n mappings:\n - wireguard_download:\n ssh_authorized_key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOh9BTe81DC6A0YZALsq9dWcyl6xjjqlxWPwlExTFgBt user@host\n system_user: signstar-wireguard-download\nyubihsm2:\n connections:\n - mock\n mappings:\n - admin:\n authentication_key_id: 1\n - audit_log:\n authentication_key_id: 2\n ssh_authorized_key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPkpXKiNhy39A3bZ1u19a5d4sFwYMBkWQyCbzgUfdKBm user@host\n system_user: yubihsm2-audit-log\n - backup:\n authentication_key_id: 3\n ssh_authorized_key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINrIYA+bfMBThUP5lKbMFEHiytmcCPhpkGrB/85n0mAN user@host\n system_user: yubihsm2-backup\n - certificate_retrieval:\n authentication_key_id: 4\n ssh_authorized_key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDfCJD+futTp8vlKxx2Rd1hqY+vnMp9iXSRTeCLhcGmr user@host\n system_user: yubihsm2-certificate-retrieval\n - hermetic_audit_log:\n authentication_key_id: 5\n system_user: yubihsm2-hermetic-audit-log\n - signing:\n authentication_key_id: 6\n key_setup:\n key_type: Curve25519\n key_mechanisms:\n - EdDsaSignature\n signature_type: EdDsa\n key_context:\n openpgp:\n notations:\n test: value\n user_ids:\n - Foobar McFooface <foobar@mcfooface.org>\n version: \"4\"\n domain: 1\n signing_key_id: 1\n ssh_authorized_key: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOh96uFTnvX6P1ebbLxXFvy6sK7qFqlMHDOuJ0TmuXQQ user@host\n system_user: yubihsm2-signing\n";Expand description
Config with YubiHSM2 mockhsm backend.
- systemd-creds for administrative secrets
- plaintext for non-administrative secrets