{% extends "base.html" %} {% block content %} ← Back to dashboard
Authority details

{{ authority['name'] }}

This server's certificate authority and public trust artifacts.

{{ 'Active' if active else 'Inactive' }}

Authority identity

{{ authority['role'] }}
{% if authority['revoked_at'] %}

Revoked {{ authority['revoked_at'] }}: {{ authority['revocation_reason']|replace('_', ' ') }}

This CA is archived. Its certificates, revocation data and audit history are retained. Manage or initialize the current CA.

{% endif %} {% if block_reason %}

{{ block_reason }}

{% endif %}

This local CA's private key is not available for download.

Subject{{ authority['common_name'] }}
Serial{{ authority['serial_number'] }}
Parent{{ 'Self-signed root' if authority['role'] == 'root' else 'External parent (public chain only)' }}
Valid from{{ authority['not_before'] }}
Valid to{{ authority['not_after'] }}
Downloads {% if authority['state'] == 'active' %} certificate full chain revocation list (CRL) {% else %}CSR{% endif %}
{% if can_manage('admin') and not authority['revoked_at'] %}
Revoke this authority

Disabling this local CA stops its issuance. Request revocation on its parent server and distribute the updated CRL. This cannot be undone.

After revocation, you can initialize a new CA on this server. This CA and its history remain archived.

{% if authority['role'] != 'root' %}

The external parent must revoke this CA certificate; disabling this server cannot update a remote CRL.

{% else %}

This root must also be removed from relying-party trust stores. Disabling it here cannot revoke external trust.

{% endif %}
{% endif %}

Subordinate certificates (remote CAs)

{% if child_authorities %} {% else %}

No subordinate CAs yet.

{% endif %}

Issued certificates

{% if issued_certificates %} {% else %}

No certificates issued from this authority yet.

{% endif %}
{% if can_manage('admin') and authority['revoked_at'] %}
Permanent deletion

Delete revoked authority

This permanently deletes {{ authority['name'] }} and its associated data from this installation. This cannot be undone.

The CA's local certificate and CRL download URLs will stop working. Its display name becomes available for a new CA. Audit records remain.

Keys managed by PKCS#11 (including SoftHSM) or Azure Key Vault and files already uploaded to a publication server are not deleted automatically.

{% endif %} {% endblock %}