{% extends "base.html" %} {% block content %}
Certificate lifecycle

{{ certificate['common_name'] }}

Certificate identity, downloads and renewal history.

Certificate inventory

Certificate details

Serial number
{{ certificate['serial_number'] }}
Issuer
{{ certificate['authority_name'] }}
Profile
{{ certificate['profile'] }}
SANs
{{ certificate['subject_alt_names'] or 'None' }}
Valid from
{{ certificate['not_before'] }}
Valid until
{{ certificate['not_after'] }}
Status
{% if certificate['revoked_at'] %}Revoked{% elif certificate['not_after'] <= now %}Expired{% elif issuer_block_reason %}Issuer inactive{% else %}Active{% endif %}
Download certificateDownload chain{% if key_download_enabled and certificate['private_key_pem'] %}Download key{% endif %}

Renewal history

Predecessor
{% if predecessor %}{{ predecessor['common_name'] }} · {{ predecessor['serial_number'] }}{% else %}No retained predecessor{% endif %}
Successor
{% if successor %}{{ successor['common_name'] }} · {{ successor['serial_number'] }}{% else %}Not renewed{% endif %}
{% if not successor and not certificate['revoked_at'] and can_manage('admin', 'operator') %}Renew certificate{% endif %}

Ownership & deployment

Keep the responsible person and the service using this certificate together.

{% if can_manage('admin','operator') %}
{% if can_manage('admin') %}
Check the deployed TLS certificate

The monitoring service connects to this endpoint and checks its hostname, trust chain and certificate fingerprint. Use a TLS service such as HTTPS or LDAPS; STARTTLS is not supported.

Private network services are supported. Loopback, link-local and metadata addresses are blocked. On renewal, these checks follow the successor certificate.

{% endif %}
{% else %}
{% for field,label in [('owner','Owner'),('service_name','Service'),('deployment_host','Deployment location'),('environment','Environment'),('tags','Tags'),('notes','Notes')] %}
{{ label }}
{{ certificate[field] or 'Not set' }}
{% endfor %}
{% endif %}
{% if certificate['tls_enabled'] or endpoint_check %}

Deployed certificate

{{ endpoint_check['status'] if endpoint_check else 'Pending check' }}

{{ certificate['tls_host'] }}:{{ certificate['tls_port'] }}

{% if endpoint_check %}

{{ endpoint_check['detail'] }}

Last checked
{{ endpoint_check['checked_at'] }}
Presented subject
{{ endpoint_check['observed_subject'] or 'Unavailable' }}
Presented expiry
{{ endpoint_check['observed_not_after'] or 'Unavailable' }}
Presented SHA-256
{{ endpoint_check['observed_sha256'] or 'Unavailable' }}
{% else %}

The next monitoring cycle will check this endpoint. Use Monitoring to run a check immediately.

{% endif %}
{% endif %} {% endblock %}