{% extends "base.html" %} {% block content %}

Assurance & evidence

Security posture

Technical controls for your CA operation. Organizational controls and an independent BSI assessment remain necessary.

Local CA boundary{{ '1 / 1' if authority else '0 / 1' }}
MFA-enrolled administrators{{ enrolled_admins }}
Verified audit events{{ checkpoint.event_count if checkpoint else 'Failed' }}
{% if integrity_error %}

{{ integrity_error }}

{% else %}

Audit chain verified. Records are protected by chained SHA-256 hashes, keyed authentication and append-only database guards.

{% endif %}
Signing readiness
{{ block_reason or 'CA is active and its required parent status is current.' }}
Independent CA approval
Subordinate certificates require a different administrator to approve the recorded CSR.
Key protection
{{ key_backend_label }}. CA private-key downloads are disabled.
Authentication
Local, LDAP or OIDC first factor, followed by mandatory application TOTP.

Audit evidence

Archive exports in an independently protected retention system. Compare the checkpoint against earlier exports to detect replacement or rollback. A host administrator with access to the application secrets can rewrite local evidence.

{% if checkpoint %}{{ checkpoint.head_hash }}{% endif %} {% if legacy_events %}

{{ legacy_events }} existing events were sealed during migration. Their integrity before migration cannot be established by this chain.

{% endif %} {% if can_manage('admin','auditor') and not integrity_error %}

Export verified audit evidence

{% endif %}

Remaining operating requirements include approved HSM selection, key ceremonies, external log retention, incident procedures, backup and recovery exercises, CP/CPS and independent assessment. This status page is not a BSI certification.

{% endblock %}