docs/documentation/platform/pki/certificates/policies.mdx
A certificate policy is a policy structure specifying permitted attributes for requested certificates. This includes constraints around subject naming conventions, SAN fields, key usages, and extended key usages.
Each certificate requested against a certificate profile is validated against the policy bound to that profile. If the request fails any criteria included in the policy, the certificate is not issued. This helps administrators enforce uniformity and security standards across all issued certificates.
To create a certificate policy, head to your Certificate Management Project > Certificate Manager > Certificate Policies and press Create Policy.
Here's some guidance on each field:
tls-server.example.com or *.example.com and whether it is allowed or denied.example.com or *.example.com, and an allow or deny flag.SHA256-RSA, SHA512-RSA, etc.RSA-2048, RSA-4096, etc.CA:TRUE property is set. Options are: