Creating a Certificate Authority

Use the Certificates service to create a root certificate authority (CA) or a subordinate CA.

You must already have a root CA to create a subordinate CA.

You must have the appropriate level of security access to create a CA. For more information, see Required IAM Policy.

Creating a CA requires you to have access to an existing hardware-protected, asymmetric encryption key from the Oracle Cloud Infrastructure (OCI) Vault service. For more information, see Overview of Vault.

When you create a CA with a certificate revocation list (CRL), you can specify an OCI Object Storage bucket where you want to store the CRL. The bucket must already exist at the time you create the CA. The bucket must also be a dedicated bucket that you don't use for any other purpose or to store the CRL of any other CA.