PingOne Advanced Services

Creating and updating virtual hosts

You and your administrators can create and update virtual host certificates and TLS configurations yourselves.

Platform version 2.0.x contains enhancements that makes this functionality possible. To use it, we’ll need to migrate certificates and configurations from GitOps orchestration to the API.

  • If you’re using platform version 1.19.2.0 or earlier, a Ping Identity representative will reach out to you to complete this migration.

  • If you’re using platform 2.0.0 or later, you can request this migration at any time by submitting a service request.

Keep the following in mind:

  • After you create or update a configuration, it will take some time for the virtual host to become available.

  • Virtual host configurations are automatically replicated to child regions in PingOne Advanced Services.

  • It is up to the user to keep track of the certificate’s fullchain and private key because neither the admin console nor API will return that information.

  • Configurations can only be rolled back once. Then, the configuration needs to be updated at least once before a rollback can be performed again.

Limitations include:

  • You cannot currently create or update the following items yourself. Submit a service request instead.

    • MTLS configurations.

    • Configurations that need custom annotations, such as annotations of Cross-Origin Resource Sharing (CORS) responses.

    • Private Ingress configurations.

    • EC or ECC TLS certificates.

  • Virtual hosts cannot be created for the PingFederate Admin UI or the PingAccess Admin UI in PingOne Advanced Services.

Before you begin

Ensure you have access to the administrative API. Learn more in Accessing the administrative API. Learn more about using the API in Using the API interactive documentation.