: Overview: Request Policies
Focus
Focus

Overview: Request Policies

Table of Contents

Overview: Request Policies

Request policies define the certificate policies that are enforced whenever new certificates are issued.
A request policy combines a CA account selection with certificate rules in a single place. When you create a request policy, you define the rules that reflect your organization’s certificate security policies for requesting or renewing certificates.
Note: Request policies are parent TSG resources. Only users with the Superuser role in the parent TSG can create or modify request policies. Request policies must be explicitly shared with child TSGs for users in those TSGs to request certificates using the request policy.
Here are some of the benefits of request policies:
  • Enable consistent certificate requests by applying predefined security policies, so certificates are issued according to approved standards.
  • Speed up certificate issuance by requiring only the necessary input. All other settings are predefined or enforced by policy.
You can create as many request policies as needed, and edit or delete them at any time.
Most request policies include at least the following settings:
  • Request policy name
  • CA account
  • Issuing rules
  • Additional fields that are specific to the selected CA account
Depending on the CA, additional settings may be required. For example, a request policy for DigiCert includes a Product Option field.
What is the default request policy? Next-Gen Trust Security includes a default request policy as an example. This policy should only be used for testing or evaluation and is not intended for production use. In Production, create your own request policy instead.
To prevent inappropriate certificate issuance, Palo Alto Networks recommends not providing the default request policy to resource owners.

What's Next