{% extends "base.html" %} {% block content %}
Administration

Settings

Configure your organization, certificate policy, and HTTPS service.

Administrator access

Organization and PKI policy

Policy changes apply to future operations and newly issued certificates.

Used for CRL distribution URLs in newly issued certificates. Previously issued certificates keep their original URLs.

Certificate and session policy

Set validity limits and the console's session timeout.

End-entity key downloads are audited. CA private keys can never be downloaded. Operators and auditors cannot download keys.

HTTPS service

Manage the packaged service's listener and web certificate.

127.0.0.1 permits local connections; 0.0.0.0 listens on all IPv4 interfaces. The packaged service automatically restarts after listener or certificate changes. Reconnect using the new address and port.

Upload both files to replace the initial HTTPS certificate. The server certificate must contain a Subject Alternative Name and match the private key. Leave both blank to retain the current certificate.

Changes are recorded in the audit log.

{% endblock %}