Cryptographic custody
Choose where this server's current CA key is generated and used. After revoking a CA, its replacement receives a fresh key. External providers sign certificates, CSRs and CRLs without returning the private key.
{% if authority %}This CA is permanently bound to {{ labels[authority.key_backend] }}. Only provider credentials can be updated; replacements are verified against the existing key.
{% endif %}