Server identity

Local certificate authority

{% if authority %}View authority{% endif %}
{% if authority %}
{{ icon('shield') }}
{{ authority['name'] }}
{{ authority['role'] }}{{ 'Signing blocked' if block_reason else 'Operational' }}

This is the only CA on this server. Other trust tiers run on separate servers. Its private key cannot be exported through the console.

{% if block_reason %}

{{ block_reason }}

{% endif %}

{% if authority['csr_pem'] %}Download CA CSR{% endif %} {% if authority['state'] == 'active' %} CA certificate CA chain CRL (DER) CRL (PEM) {% endif %}

{% if can_manage('admin') and authority['state'] == 'pending' and not authority['revoked_at'] %}

Activate this CA

Have the parent server sign the downloaded CSR. Import the returned certificate and its parent chain. Verify the root fingerprint through a trusted channel before importing.

{% endif %} {% if can_manage('admin') and authority['state'] == 'active' and authority['role'] != 'root' %}
Parent revocation status

Import a current, signed full CRL from every parent server, immediate issuer first and root last. Missing, expired, or revoked parent status blocks issuance. Re-import before the CRLs expire.

{% endif %} {% elif can_manage('admin') %}

Initialize exactly one CA on this server. Choose a Root CA, or generate a CSR for an Intermediate or Issuing CA whose parent runs on another server. This identity cannot be replaced through the console.

{% else %}

A security administrator must initialize this server's CA.

{% endif %}
{% if authority and authority['role'] != 'issuing' %} {% if can_manage('admin') %}
Approval workflow

Request subordinate CA signing

Two-person approval

Submit a CSR generated on the subordinate CA's own server. A different administrator must review and approve the request. No subordinate private key is generated or stored here.

{% endif %}

CA signing requests

Most recent 100 requests. Approval signs the exact recorded CSR and policy shown below.

{% for entry in ca_requests %}
#{{ entry['id'] }} · {{ entry['common_name'] }} {{ entry['status'] }}

Requested by {{ entry['requester'] }} · {{ entry['role'] }} · {{ entry['validity_days'] }} days

CSR SHA-256: {{ entry['fingerprint'] }}

{% if entry['status'] == 'pending' and can_manage('admin') %} {% if entry['requested_by'] != current_user['id'] %}

Verify the CSR fingerprint and the requester’s authorization through your established approval procedure.

{% else %}

A different administrator must approve your request.

{% endif %}
{% endif %}
{% else %}
No CA signing requests.
{% endfor %}

Issued subordinate CA certificates

Public certificates for CAs on other servers. This server holds no private keys for them. Most recent 100 certificates.

{% for entry in issued_authorities %}{% else %}{% endfor %}
Common nameRoleStatus / expiresArtifacts
{{ entry['common_name'] }}{{ entry['role'] }} {{ 'Revoked' if entry['revoked_at'] else 'Issued' }}
{{ entry['not_after'][:10] }}
Certificate Parent chain {% if can_manage('admin') and not entry['revoked_at'] %}
Revoke

Permanent. Publish and distribute the updated CRL to the subordinate server and relying parties.

{% endif %}
No subordinate certificates issued.
{% endif %}