Previous local CAs and their public artifacts remain available. Revocation is permanent.
| Authority | Role | Revoked | Artifacts |
|---|---|---|---|
| {{ archived['name'] }} {{ archived['common_name'] }} |
{{ archived['role'] }} | Revoked {{ archived['revoked_at'][:10] }} |
{% if archived['state'] == 'active' %} Certificate Chain CRL {% elif archived['csr_pem'] %}CSR{% endif %} |
Submit a CSR generated on the subordinate CA's own server. A different administrator must review and approve the request. No subordinate private key is generated or stored here.
Most recent 100 requests. Approval signs the exact recorded CSR and policy shown below.
Requested by {{ entry['requester'] }} · {{ entry['role'] }} · {{ entry['validity_days'] }} days
Signing authority: {{ entry['authority_name'] }}{% if entry['authority_id'] not in active_authority_ids %} Issuer inactive{% endif %}
CSR SHA-256: {{ entry['fingerprint'] }}
{% if entry['status'] == 'pending' and can_manage('admin') and authority and authority['role'] != 'issuing' and entry['authority_id'] == authority['id'] and entry['authority_id'] in active_authority_ids %} {% if entry['requested_by'] != current_user['id'] %} {% else %}A different administrator must approve your request.
{% endif %} {% endif %}Public certificates for CAs on other servers. This server holds no private keys for them. Most recent 100 certificates.
| Common name | Issuer / role | Status / expires | Artifacts |
|---|---|---|---|
| {{ entry['common_name'] }} | {{ entry['authority_name'] }} {{ entry['role'] }} |
{% if entry['revoked_at'] %}Revoked{% elif entry['authority_id'] not in active_authority_ids %}Issuer inactive{% else %}Issued{% endif %} {{ entry['not_after'][:10] }} |
Certificate
Parent chain
{% if can_manage('admin') and not entry['revoked_at'] %}
Revoke |
| No subordinate certificates issued. | |||