Skip to main content
Version: 0.17

Use an operator-supplied CSR

Available from Core 0.17.0. A workspace manager or administrator can open Certificates → CSR workflows, or choose Add new CSR beside an existing certificate to rotate that certificate. Enable CertOps first.

Upload and export the public CSR​

Generate a CSR where its private key lives, using your host's existing tooling. TokenTimer does not generate a key or CSR for this workflow. Upload only the public PEM CSR, then select an existing target or name the host, load balancer, appliance, or other location that will receive the signed certificate. Private keys and key packages are rejected.

The request starts in pending_signature. Export public CSR downloads the CSR for your certificate authority. Re-uploading the same CSR for the same target reuses its workflow; a cancelled workflow can be restarted with that upload.

Import the signed certificate and review names​

Have your CA sign the CSR, then use Import signed certificate to upload the public leaf certificate followed by any public CA chain. TokenTimer verifies that the leaf certificate's public key matches the CSR. It does not accept an unrelated key or silently replace another managed certificate identity.

The request moves to signed_pending_install. Review any names the CA added or omitted, then choose Acknowledge name changes. An observation can be recorded during review, but the signed certificate is not promoted until name review is complete. The previous certificate stays intact during a rotation.

Complete installation​

Install the signed certificate using your host tooling. A matching agent, controller, or endpoint observation can complete the workflow after name review. A different managed identity at the target raises an identity conflict: review both certificate records and reconcile the identities before proceeding.

For an unmonitored target created through the API or a manual import, Confirm installation records your audited manual attestation. It does not deploy the certificate or perform a network check. Monitored targets require a matching observation.

Completion promotes the signed certificate and preserves the selected certificate identity and deployment history. Cancel stops a pending workflow without changing the host or its key; a completed workflow cannot be cancelled.

API access​

Use the CSR operations in the API reference under /api/v1/workspaces/{id}/certops/csrs. Both reads and writes require an authenticated human session, workspace membership, and manager-or-administrator access. Session-authenticated writes need the paired CSRF header; machine and worker tokens cannot manage these workflows.