{% extends "base.html" %} {% block content %}

Public trust information

CRL & AIA publication

Publish this server's signed revocation list and public CA certificates to a separate distribution server. Clients retrieve them over HTTP(S); PKIMaster uploads them over SFTP.

After initializing a replacement CA, configure separate publication URLs and a separate SFTP directory before enabling uploads. Keep the archived CA's CRL and AIA URLs and files available for its existing certificates.

Automatic publication{{ 'Enabled' if provider.enabled else 'Disabled' }}
Published CRL{{ state.last_published_crl_number or 'Not yet' }}
Queue{{ 'Pending' if state.generation > state.published_generation else 'Current' }}
{% if state.last_error %}

{{ state.last_error }}

{% endif %}
Last successful upload
{{ state.last_success or 'No successful publication yet' }}
Current CRL expires
{{ cached.next_update if cached and cached.next_update else 'A fresh CRL will be generated before publication' }}
{% if state.next_attempt %}
Retry after
{{ state.next_attempt }} ({{ state.failures }} consecutive failures)
{% endif %}

Distribution settings

Public retrieval URLs

These addresses are embedded in newly issued certificates, including subordinate CA certificates. Existing certificates keep their original addresses. Keep those locations available. Leave blank to use the public base URL from Settings.

The AIA address must return this CA's DER certificate. It does not provide OCSP. Configure the distribution web server to serve ca.crl as application/pkix-crl and ca.cer as application/pkix-cert, without login.

SFTP destination

When disabled, saving updates only the public URLs and keeps the stored SFTP connection settings.

Obtain the fingerprint through a trusted channel. Unknown or changed host keys are rejected before authentication. Use a dedicated SFTP account restricted to this CA's directory.

Credentials are stored encrypted and never displayed. Re-enter credentials when changing the host, account or host key. This SSH key is separate from the CA signing key.

The destination directory must already exist and support atomic POSIX rename. Uploads replace ca.cer, chain.pem and finally ca.crl. The APT timer runs every minute, renews CRLs before expiry and retries failures with a delay of up to one hour. No CA private keys are uploaded.

{% endblock %}