: Overview: Request Policies
Focus
Focus

Overview: Request Policies

Table of Contents

Overview: Request Policies

Request policies define the certificate policies that are enforced whenever new certificates are issued.
A request policy combines a CA account selection with certificate rules in a single place. When you create a request policy, you define the rules that reflect your organization’s certificate security policies for requesting or renewing certificates.
Note: Request Policies belong to the tenant. With a workspace selected the page is read only: you can open a request policy and see its settings, but creating, editing, and deleting require the Superuser role and Tenant selected in the workspace switcher. A request policy has to be authorized for a workspace before anyone working in that workspace can request certificates with it, which you do from Authorized Workspaces on the policy itself. See Workspace-Scoped Resources.
Here are some of the benefits of request policies:
  • Enable consistent certificate requests by applying predefined security policies, so certificates are issued according to approved standards.
  • Speed up certificate issuance by requiring only the necessary input. All other settings are predefined or enforced by policy.
You can create as many request policies as needed, and edit or delete them at any time.
Most request policies include at least the following settings:
  • Request policy name
  • CA account
  • Issuing rules
  • Additional fields that are specific to the selected CA account
Depending on the CA, additional settings may be required. For example, a request policy for DigiCert includes a Product Option field.
What is the default request policy? Next-Gen Trust Security includes a default request policy as an example. This policy should only be used for testing or evaluation and is not intended for production use. In Production, create your own request policy instead.
To prevent inappropriate certificate issuance, Palo Alto Networks recommends not providing the default request policy to resource owners.

What's Next