{% extends "base.html" %} {% macro template_form(item=None) %}

The installation lifetime limit and issuer expiry also apply.

Each domain includes itself and its subdomains. Empty allows all DNS names; ACME requires an explicit domain list.

When IP addresses are enabled, an empty network list allows all IP addresses.

Who can use this template{% for value,label in [('admin','Administrators'),('operator','Operators'),('acme','ACME accounts')] %}{% endfor %}
{% endmacro %} {% block content %}
Issuance policy

Certificate templates

Consistent lifetimes, permitted names and access rules for every issuance channel.

{{ templates|length }} templates

Create a template

New certificate template{{ template_form() }}
{% for item in templates %}

{{ item.name }}

{{ item.description or 'Certificate issuance policy' }}

{{ 'Enabled' if item.enabled else 'Disabled' }}

{{ item.profile }} · Default {{ item.default_validity_days }} days · Maximum {{ item.max_validity_days }} days · Revision {{ item.revision }}

Domains: {{ item.dns_suffixes|join(', ') or 'All DNS names' }} · Access: {{ item.roles|join(', ') }}

Edit policy{{ template_form(item) }}
{% endfor %} {% endblock %}