{% extends "base.html" %} {% block content %}

Cryptographic custody

Key storage

Choose where this server's single CA key is generated and used. External providers sign certificates, CSRs and CRLs without returning the private key.

{% if authority %}

This CA is permanently bound to {{ labels[authority.key_backend] }}. Only provider credentials can be updated; replacements are verified against the existing key.

{% endif %}
{% if authority %}{% endif %}

Encrypted software keys and SoftHSM are software protection. Azure RSA-HSM requires a suitable Premium vault or Managed HSM; selecting Azure RSA uses software-backed keys.

PKCS#11 / SoftHSM
{% if not authority %} {% endif %}
{% if not authority %}

The officer PIN is used once and is not stored. Preserve it in your key-ceremony records. Existing tokens are never reset.

{% endif %}
Azure Key Vault / Managed HSM
{% if not authority %}{% endif %}

The selected key version is pinned. Vault key rotation does not silently replace a CA identity. Configure a dedicated identity with only the required key get, create (for new keys) and sign permissions.

{% endblock %}