Issuing a Subordinate Certificate Authority

Issue a subordinate certificate authority (CA).

You must already have a root CA in Oracle Cloud Infrastructure Certificates to create a subordinate CA. You can issue a subordinate CA from any other CA as long as you don't exceed the total allowable number of CAs in the tenancy.

Creating a CA requires you to have access to an existing hardware-protected, asymmetric encryption key from the Oracle Cloud Infrastructure Vault service. For more information, see Overview of Vault.

When you create a CA with a certificate revocation list (CRL), you can specify an OCI Object Storage bucket where you want to store the CRL. The bucket must already exist at the time you create the CA.