Certificates in Secryn represent cryptographic certificates used for TLS, internal services, and infrastructure authentication. Certificates belong to a vault and are governed by project-level access and optional restricted vault rules.
Certificates are immutable and non-versioned. Once created or uploaded, they cannot be edited.
To create a certificate:
An audit log entry is recorded.
When generating a certificate:
If changes are required, create a new certificate.
When uploading a certificate:
This ensures Secryn remains a source of truth and does not alter uploaded material.
Certificates in Secryn:
If renewal or replacement is required:
This design prevents silent modification of cryptographic material.
Certificates may be marked as public.
When public visibility is enabled:
Important:
Use public visibility only when required.
Certificates support:
Expiration:
Expired certificates remain visible but inactive.
Certificates can be enabled or disabled.
Disabling does not remove the certificate record.
Certificates can be tagged for organization and filtering.
Tags:
Access to certificates is determined by:
Admins and Project Managers typically manage certificates. Contributors may create certificates if permitted by vault rules.
Certificates can be accessed using:
All access is logged.
Certificates in Secryn follow these principles:
Secryn prioritizes cryptographic integrity and lifecycle clarity.