Skip to content

Overview: request policies

Request policies are used to configure security policies that are enforced whenever new certificates are issued.

A request policy combines the selection of a CA account with rules that enforce certificate policies, all in a single location. And when you create your request policy, you define the rules that reflect your company's certificate security policies for requesting or renewing certificates.

Note

Request policies can be created or modified only by a System Administrator or PKI Administrator.

Here are some of the benefits of request policies:

  • Facilitates self-service by letting other machine owners more easily request certificates without having to depend on a PKI team, or even understand crypto. Because the request policy includes your organization's security policies, they can simply use the request policy with your pre-defined settings already in place.

  • Request policies also help to speed up certificate issuance by delivering only required information; everything else is set up by default, or controlled by policy.

You can create as many request policies as you need, and then edit or delete them at any time.

Most request policies contain at least these basic settings:

  • Template Name
  • CA Account
  • Issuing Rules
  • Additional fields that are linked to a specific CA account

Depending on the CA, some might include additional settings. For example, a request policy for DigiCert includes an additional field called Product Option.

What is the default request policy?

Certificate Manager - SaaS includes a default request policy as an example. This policy should only be used for testing or evaluation. For Production use cases, create your own request policy.

To prevent inappropriate certificate issuance, Palo Alto Networks recommends not providing the default request policy to resource owners.

What's next