Parameters that should be specified as variables (currently hardcoded): - ssh key type (ecdsa, rsa), newCA and bastion roles - certificate validity period, existingCA role