{% extends "base.html" %} {% block content %}

Operations

Automation

Keep parent revocation status current and deliver recovery backups and audit evidence to your external archive.

Job status

{% for key, label in [('parent','Parent CRLs'),('backup','Encrypted backup'),('audit','Audit archive')] %} {% endfor %}
JobScheduleLast successLatest result
{{ label }}{% if provider[key ~ '_enabled'] %}Every {{ provider.backup_interval_hours if key == 'backup' else provider[key ~ '_interval_minutes'] }} {{ 'hours' if key == 'backup' else 'minutes' }}{% else %}Disabled{% endif %}{{ jobs[key].last_success or 'Never' }}{% if jobs[key].last_error %}Failed {{ jobs[key].last_error }}{% elif jobs[key].last_success %}Successful{% else %}Not run{% endif %}{% if key == 'audit' and jobs[key].last_cursor %}
Archived through event {{ jobs[key].last_cursor }}{% endif %}

Failed deliveries retry with backoff. Monitoring reports failures and overdue runs through your configured notification channel.

{% if backup_checksum %}

Last delivered backup SHA-256: {{ backup_checksum }}

Retain this checksum independently of the SFTP archive. It can be checked before recovery.

{% endif %}

Schedule and destination

Parent CRL synchronization

For an activated subordinate CA, enter one HTTP(S) URL per ancestor, starting with its immediate issuer and ending with the root. Expired, unsigned and older CRLs are rejected. A verified revocation permanently disables the local CA.

{% if authority %}

Current CA: {{ authority.name }} ({{ authority.role }})

{% endif %}
Encrypted recovery backups

The CA stores only your recovery public key. The private recovery key is needed to restore a scheduled backup on a fresh host. Encryption protects confidentiality and integrity, but does not prove who created a backup: anyone holding the public key can create an encrypted archive. Restore only from a trusted source, preferably using an independently retained archive checksum.

Generation requires a browser with Web Crypto over HTTPS. You may also paste a dedicated RSA-3072 or RSA-4096 public key below.

SHA-256 public-key fingerprint: {{ fingerprint or 'Not configured' }}

Existing backups remain encrypted for their original key. Keep older recovery keys for as long as those backups are retained. External hardware/HSM keys remain subject to their provider's recovery process.

External audit evidence

Audit archives use immutable filenames and are never removed by backup retention. A conflicting external checkpoint stops delivery and raises a finding. Audit archives contain event details and should be kept private.

External SFTP archive

Use a dedicated directory and account. Obtain the server fingerprint through a trusted channel. A changed host, account, fingerprint or authentication method requires re-entering its credential.

{% endblock %}