diff --git a/docs/documentation/platform/pki/certificate-templates.mdx b/docs/documentation/platform/pki/certificate-templates.mdx new file mode 100644 index 000000000..9afaf456f --- /dev/null +++ b/docs/documentation/platform/pki/certificate-templates.mdx @@ -0,0 +1,58 @@ +--- +title: "Certificate Templates" +sidebarTitle: "Certificate Templates" +description: "Learn how to use certificate templates to enforce policies." +--- + +## Concept + +In order to ensure your certificates follow certain policies, you can use certificate templates during the issuance and signing flows. + +A certificate template is linked to a certificate authority. It contains custom policies for certificate fields, allowing you to define rules based on your security policies. + +## Workflow + +The typical workflow for using certificate templates consists of the following steps: + +1. Creating a certificate template attached to an existing CA along with defining custom rules for certificate fields. +2. Selecting the certificate template during the creation of new certificates. + + + Note that this workflow can be executed via the Infisical UI or manually such + as via API. + + +## Guide to using Certificate Templates + +In the following steps, we explore how to issue a X.509 certificate using a certificate template. + + + + + + + To create a certificate template, head to your Project > Internal PKI > Certificate Templates and press **Create Certificate Template**. + + ![certificate-template create template dashboard](/images/platform/pki/certificate-template/create-template-dashboard.png) + + Here, set the **Issuing CA** to the CA you want to issue certificates under when the certificate template is used. + + ![certificate-template create template modal](/images/platform/pki/certificate-template/create-template-form.png) + + Here's some guidance on each field: + - Template Name: A descriptive name for the certificate template. + - Issuing CA: The Certificate Authority (CA) that will issue certificates based on this template. + - Certificate Collection: The collection where certificates issued with this template will be added. + - Common Name (CN): The regular expression used to validate the common name in certificate requests. + - Alternative Names (SANs): The regular expression used to validate subject alternative names in certificate requests. + - TTL: The maximum Time-to-Live (TTL) for certificates issued using this template. + + + + Once you have created the certificate template from step 1, you can select it when issuing certificates. + + ![certificate-template select template](/images/platform/pki/certificate-template/select-template.png) + + + + diff --git a/docs/images/platform/pki/certificate-template/create-template-dashboard.png b/docs/images/platform/pki/certificate-template/create-template-dashboard.png new file mode 100644 index 000000000..6f193effa Binary files /dev/null and b/docs/images/platform/pki/certificate-template/create-template-dashboard.png differ diff --git a/docs/images/platform/pki/certificate-template/create-template-form.png b/docs/images/platform/pki/certificate-template/create-template-form.png new file mode 100644 index 000000000..e69791edd Binary files /dev/null and b/docs/images/platform/pki/certificate-template/create-template-form.png differ diff --git a/docs/images/platform/pki/certificate-template/select-template.png b/docs/images/platform/pki/certificate-template/select-template.png new file mode 100644 index 000000000..c10031a45 Binary files /dev/null and b/docs/images/platform/pki/certificate-template/select-template.png differ diff --git a/docs/mint.json b/docs/mint.json index 98d6f01ac..9496ffffe 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -108,6 +108,7 @@ "documentation/platform/pki/overview", "documentation/platform/pki/private-ca", "documentation/platform/pki/certificates", + "documentation/platform/pki/certificate-templates", "documentation/platform/pki/alerting" ] },