Managed Certificates

The Managed Certificates page in the Admin section is the working surface for Signotaur's certificate-management system. From here, administrators issue and renew certificates, register them for use by the SignotaurTool client, and configure the issuers that produce them.

The entire Managed CA area is an Enterprise feature. Without an Enterprise license the Managed Certificates navigation item is hidden, and navigating to this page directly redirects to the Licenses page. Issuing and renewing certificates (and automatic renewal) require Enterprise. A 14-day Enterprise trial is available from the Licenses page. See Editions & Licensing.

A managed certificate is one that Signotaur itself has issued (from its Internal CA or from ADCS) and renews automatically before it expires. The page lists both web (TLS) and code-signing managed certificates together. The server's own HTTPS certificate is selected and monitored on a separate page; see Web Certificate.

Page Layout

The page is organised into tabs. The first tab is operational; the rest configure the feature:

  • Certificates: the table of issued certificates. Issue, renew, register, and delete certificates, and view the CA hierarchy.
  • Settings: choose which issuers are enabled, set the retention period, and turn automatic renewal on or off.
  • Renewal Policy: renewal thresholds and check intervals, and the cleanup policy for replaced certificates. (Shown only when renewal is enabled.)
  • Notifications: email warnings for Root and Intermediate CA expiry.
  • Internal CA: defaults for the Internal CA. (Shown only when the Internal CA is enabled.)
  • Microsoft ADCS: connection settings and issuance defaults for the external ADCS issuer. (Shown only when ADCS is enabled.)

The page header notes the retention period: how long replaced and revoked certificates are kept before they are removed.

Before You Begin

Certificate management must be set up before this page is useful:

  • The Internal CA is opt-in; enable it on the Settings tab (or by selecting the Internal CA web-certificate mode in the installer). Once enabled, review the Internal CA settings if you want to change the issuance defaults.
  • For ADCS, enable it on the Settings tab and complete the ADCS settings first.

For the underlying concepts, see the Certificate Management section.