How to grant access to ssh-sign to the LDAP authenticated users?

Hi, with the use of LDAP auth i’ve managed to access with my ActiveDirectory users on vault.
I had a secret created before by the root user where users could retrieve a ssh-key signed by the vault server CA.

The thing is that the new users who get authenticated in vault, dont have access to that SSH-CA-KEY-SIGN resource.

How could i give acces to this SSH-KEY-SIGN resource to all my AD users?

You would do this the same way all access is managed in Vault - by writing policies and associating them with identity entities or groups (or in some cases having them linked directly to tokens by particular login methods).

I recognise this is a very general reply, but it is difficult to be more specific without more details of the current configuration that you are building on top of.

