Operator · Templates & Access

The Starter Library

Frame 40 of 107

A blank template editor is where certificate policy mistakes are born. goca doesn't hand you one: first boot on a regular instance seeds eighteen starting points — TLS server (ECDSA and PQC variants), TLS client, smartcard logon, S/MIME signing and encryption, code signing, OCSP signing, timestamping, device identity, the root-ca/ica/qualified-ica CA profiles, and the eIDAS-profile templates: QWAC, QSeal, QSigC and their PSD2 variants. (Profiles matching the eIDAS shapes — not a certification claim.)

Three deliberate choices in the seeding are worth reading as policy advice:

Treat the library as reviewed starting points, not defaults to ship blind: open each one you intend to use, read what it asserts, and make binding it a decision.

Now I know what first boot seeded — and that binding a CA is my first act.