---
title: Charmhub | Deploy Self Signed X.509 Certificates using Charmhub - The Open
  Operator Collection
description: Deploy the latest version of Self Signed X.509 Certificates on any cloud.
url: https://charmhub.io/self-signed-certificates/configurations
---

# Self Signed X.509 Certificates

[Canonical Telco](https://charmhub.io/publisher/telco-charmers "View all packages from Canonical Telco")

* [Canonical Telco](https://charmhub.io/publisher/telco-charmers "View all packages from Canonical Telco")

Platform:

24.04

22.04

1/stable 588

```
juju deploy self-signed-certificates --channel 1/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [ca-common-name](https://charmhub.io/self-signed-certificates/configurations#ca-common-name)
* [ca-country-name](https://charmhub.io/self-signed-certificates/configurations#ca-country-name)
* [ca-email-address](https://charmhub.io/self-signed-certificates/configurations#ca-email-address)
* [ca-locality-name](https://charmhub.io/self-signed-certificates/configurations#ca-locality-name)
* [ca-organization](https://charmhub.io/self-signed-certificates/configurations#ca-organization)
* [ca-organizational-unit](https://charmhub.io/self-signed-certificates/configurations#ca-organizational-unit)
* [ca-state-or-province-name](https://charmhub.io/self-signed-certificates/configurations#ca-state-or-province-name)
* [certificate-limit](https://charmhub.io/self-signed-certificates/configurations#certificate-limit)
* [certificate-validity](https://charmhub.io/self-signed-certificates/configurations#certificate-validity)
* [root-ca-validity](https://charmhub.io/self-signed-certificates/configurations#root-ca-validity)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* ca-common-name | string

  Default: self-signed-certificates-operator

  Common name to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* ca-country-name | string

  Country name to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* ca-email-address | string

  Email address to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* ca-locality-name | string

  Locality name to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* ca-organization | string

  Organization name to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* ca-organizational-unit | string

  Organizational unit to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* ca-state-or-province-name | string

  State or province name to be used by the Certificate Authority. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* certificate-limit | int

  Default: 99

  Maximum number of certificates that can be issued to a single requirer. Use -1 for allowing an unlimited number of certificates.
* certificate-validity | string

  Default: 90d

  Signed certificate validity. The given value must be followed by one of: "m" for minutes, "h" for hours, "d" for days and "w" for weeks. For example, "1m" for 1 minute, "10w" for 10 weeks. If no units are given, the unit will be assumed as days. Defaults to 90 days. This value must be equal to or shorter than half the root-ca-validity. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
* root-ca-validity | string

  Default: 365d

  RootCA certificate validity. The given value must be followed by one of: "m" for minutes, "h" for hours, "d" for days and "w" for weeks. For example, "1m" for 1 minute, "10w" for 10 weeks. If no units are given, the unit will be assumed as days. Defaults to 365 days. This value must be equal to or longer than twice the certificate-validity. Changing this value will trigger generation of a new CA certificate, revoking all previously issued certificates.
