Skip to main content
Applies to:
DuoKey Cockpit v2Certificate request workflowVault-backed CA

Overview​

Issuing a certificate under a DuoKey CA follows a request-and-approval workflow with an optional deployment step:

PhaseWhoResult
1 — RequestRequesterA pending certificate request
2 — ApproveApproverAn approved request, ready to issue
3 — IssueIssuer / CA operatorA signed, active certificate
4 — Deploy (optional)OperatorCertificate installed on a target, with rollback available

Prerequisites

  • A certificate authority to issue from (or a connected external issuer)
  • Permission to request certificates
  • A vault selected for managed key storage
  • The subject details and SANs ready

Phase 1 — Create the request​

1

Open the certificate area

In the Cockpit, go to the PKI / Certificates area and start a new certificate request under the CA you want to issue from.

2

Enter subject details

Provide the subject and any subject alternative names:

FieldRequiredExample
Certificate nameYesprod-web-server
Common Name (CN)Yeswww.example.com or *.example.com
Organization (O)YesAcme Corporation
Organizational Unit (OU)NoIT
Country (C)YesCH
State / Locality (ST / L)YesVaud / Lausanne
Subject Alternative NamesNoapi.example.com, 10.0.0.1
Tip

For a wildcard certificate, set the common name to *.example.com and add specific hosts as SAN entries where needed.

3

Choose the certificate type

Pick the purpose — Server (TLS), Client (mTLS), Code signing or Email (S/MIME). The type sets the appropriate extended key usage (for a server certificate, ServerAuth).

4

Select the key algorithm

AlgorithmCategory
RSA-2048 / RSA-4096Classical (RSA)
EC-P256 / EC-P384Classical (ECC)
ML-DSA-44 / 65 / 87Post-quantum (FIPS 204)
SLH-DSA-128F / 128SPost-quantum (FIPS 205)
ML-DSA-65 + ECDSA-P256Hybrid / composite
Warning

There is no RSA-3072, EC-P521 or 8192-bit option. Post-quantum and hybrid keys require a vault-backed issuing CA.

5

Confirm key usage and validity

A TLS server certificate uses Digital Signature + Key Encipherment. Set the validity period in days (1 year / 365 days is a common choice for TLS).

6

Select the vault and access

Choose the vault that will hold the managed key — for managed leaf certificates the key is currently generated and held in the platform's software vault — and assign the roles allowed to manage this certificate.

7

Submit

Review and submit. The request appears in Pending requests.

Phase 2 — Approve the request​

1

Open pending requests

Go to Pending requests. Each row shows the certificate name, common name, requester, date and status.

2

Review and decide

Open the request, verify the subject, SANs, type and algorithm, then approve or reject. A comment is recorded in the audit trail.

Tip

Separation of duties is enforced by permissions: approving a request is a distinct permission from requesting one, so the same person need not (and often cannot) do both.

Phase 3 — Issue the certificate​

1

Issue the approved request

From the approved request, choose Issue. The CA signs the certificate; a managed key pair is created in the vault (or your supplied CSR public key is certified).

2

Certificate is active

The issued certificate appears in the certificates list, ready to view, export or deploy.

Important

By default, exporting a certificate returns public certificate material only. With the export permission, a certificate's private key can also be downloaded (PEM or inside a PKCS#12 bundle) if it was marked exportable at issuance.

Post-issuance operations​

View and export​

Open a certificate to see its subject, SANs, validity, key usage, serial number and fingerprints, and to download it. Typical export formats are PEM and DER for the certificate and chain, plus a PKCS#12 bundle. Downloading the private key itself (as a standalone PEM, an encrypted PEM, or inside the PKCS#12 bundle) requires a separate export permission and only works for a key that was marked exportable when it was created.

Deploy to a target​

Rather than exporting and installing by hand, push the certificate directly to where it terminates TLS. Deployment jobs validate the result and can be rolled back.

TargetNotes
F5 BIG-IPDeploy cert+key or cert-only via iControl REST
Fortinet FortiGateDeploy with rollback
Azure App ServiceBind to an app service
Entra IDApp Proxy / App Registration
Apache · Nginx · IIS · JKS · Windows CAPIGeneric deploy targets

For servers you manage directly, reference the deployed material in the web-server configuration:

NginxNGINX
ssl_certificate /path/to/certificate.pem;
ssl_certificate_key /path/to/private-key.pem; # or an HSM/PKCS#11-backed key

Renew and revoke​

  • Renew before expiry — re-issue from the request, or renew through the external issuer that issued it.
  • Revoke with an RFC 5280 reason. The revocation is published in the CA's CRL and reflected by its OCSP responder.

Troubleshooting​

Next steps​