Previous local CAs and their public artifacts remain available until explicitly deleted. Revocation is permanent.
| Authority | Role | Revoked | Artifacts |
|---|---|---|---|
| {{ archived['name'] }} {{ archived['common_name'] }} |
{{ archived['role'] }} | Revoked {{ archived['revoked_at'][:10] }} |
{% if archived['state'] == 'active' %} Certificate Chain CRL {% elif archived['csr_pem'] %}CSR{% endif %} {% if can_manage('admin') %}Delete CA{% endif %} |
Submit a CSR generated on the subordinate CA's own server. A different administrator must review and approve the request. No subordinate private key is generated or stored here.
Most recent 100 requests. Approval signs the exact recorded CSR and policy shown below.
Requested by {{ entry['requester'] }} · {{ entry['role'] }} · {{ entry['validity_days'] }} days
Signing authority: {{ entry['authority_name'] }}{% if entry['authority_id'] not in active_authority_ids %} Issuer inactive{% endif %}
CSR SHA-256: {{ entry['fingerprint'] }}
{% if entry['status'] == 'pending' and can_manage('admin') and authority and authority['role'] != 'issuing' and entry['authority_id'] == authority['id'] and entry['authority_id'] in active_authority_ids %} {% if entry['requested_by'] != current_user['id'] %} {% else %}A different administrator must approve your request.
{% endif %} {% endif %}Public certificates for CAs on other servers. This server holds no private keys for them. Most recent 100 certificates.
| Common name | Issuer / role | Status / expires | Artifacts |
|---|---|---|---|
| {{ entry['common_name'] }} | {{ entry['authority_name'] }} {{ entry['role'] }} |
{% if entry['revoked_at'] %}Revoked{% elif entry['authority_id'] not in active_authority_ids %}Issuer inactive{% else %}Issued{% endif %} {{ entry['not_after'][:10] }} |
Certificate
Parent chain
{% if can_manage('admin') and not entry['revoked_at'] %}
Revoke |
| No subordinate certificates issued. | |||