Server identity

Local certificate authority

{% if authority %}View authority{% endif %}
{% if authority %}
{{ icon('shield') }}
{{ authority['name'] }}
{{ authority['role'] }}{{ 'Signing blocked' if block_reason else 'Operational' }}

This is the current CA on this server. Other trust tiers run on separate servers. Revoked CAs remain in the archive. Its private key cannot be exported through the console.

{% if block_reason %}

{{ block_reason }}

{% endif %}

{% if authority['csr_pem'] %}Download CA CSR{% endif %} {% if authority['state'] == 'active' %} CA certificate CA chain CRL (DER) CRL (PEM) {% endif %}

{% if can_manage('admin') and authority['state'] == 'pending' and not authority['revoked_at'] %}

Activate this CA

Have the parent server sign the downloaded CSR. Import the returned certificate and its parent chain. Verify the root fingerprint through a trusted channel before importing.

{% endif %} {% if can_manage('admin') and authority['state'] == 'active' and authority['role'] != 'root' %}
Parent revocation status

Import a current, signed full CRL from every parent server, immediate issuer first and root last. Missing, expired, or revoked parent status blocks issuance. Re-import before the CRLs expire.

{% endif %} {% elif can_manage('admin') %}

Initialize a CA on this server. Choose a Root CA, or generate a CSR for an Intermediate or Issuing CA whose parent runs on another server. Only one current CA is permitted. After revocation, you can initialize a new CA; the previous CA and its history are retained.

Archived CA names remain reserved until an administrator permanently deletes that CA. A deleted CA's display name can be used again. The certificate common name may match a previous CA.

{% else %}

A security administrator must initialize this server's CA.

{% endif %}
{% if archived_authorities %}

Revoked CA archive

Previous local CAs and their public artifacts remain available until explicitly deleted. Revocation is permanent.

{{ archived_authorities|length }} archived
{% for archived in archived_authorities %}{% endfor %}
AuthorityRoleRevokedArtifacts
{{ archived['name'] }}
{{ archived['common_name'] }}
{{ archived['role'] }} Revoked
{{ archived['revoked_at'][:10] }}
{% if archived['state'] == 'active' %} Certificate Chain CRL {% elif archived['csr_pem'] %}CSR{% endif %} {% if can_manage('admin') %}Delete CA{% endif %}
{% endif %} {% if can_manage('admin') and authority and authority['role'] != 'issuing' and authority['id'] in active_authority_ids %}
Approval workflow

Request subordinate CA signing

Two-person approval

Submit a CSR generated on the subordinate CA's own server. A different administrator must review and approve the request. No subordinate private key is generated or stored here.

{% endif %} {% if ca_requests or issued_authorities or (authority and authority['role'] != 'issuing') %}

CA signing requests

Most recent 100 requests. Approval signs the exact recorded CSR and policy shown below.

{% for entry in ca_requests %}
#{{ entry['id'] }} · {{ entry['common_name'] }} {{ entry['status'] }}

Requested by {{ entry['requester'] }} · {{ entry['role'] }} · {{ entry['validity_days'] }} days

Signing authority: {{ entry['authority_name'] }}{% if entry['authority_id'] not in active_authority_ids %} Issuer inactive{% endif %}

CSR SHA-256: {{ entry['fingerprint'] }}

{% if entry['status'] == 'pending' and can_manage('admin') and authority and authority['role'] != 'issuing' and entry['authority_id'] == authority['id'] and entry['authority_id'] in active_authority_ids %} {% if entry['requested_by'] != current_user['id'] %}

Verify the CSR fingerprint and the requester’s authorization through your established approval procedure.

{% else %}

A different administrator must approve your request.

{% endif %}
{% endif %}
{% else %}
No CA signing requests.
{% endfor %}

Issued subordinate CA certificates

Public certificates for CAs on other servers. This server holds no private keys for them. Most recent 100 certificates.

{% for entry in issued_authorities %}{% else %}{% endfor %}
Common nameIssuer / roleStatus / expiresArtifacts
{{ entry['common_name'] }}{{ entry['authority_name'] }}
{{ entry['role'] }}
{% if entry['revoked_at'] %}Revoked{% elif entry['authority_id'] not in active_authority_ids %}Issuer inactive{% else %}Issued{% endif %}
{{ entry['not_after'][:10] }}
Certificate Parent chain {% if can_manage('admin') and not entry['revoked_at'] %}
Revoke

Permanent. Publish and distribute the updated CRL to the subordinate server and relying parties.

{% endif %}
No subordinate certificates issued.
{% endif %}