Status of certificate requests

Requests for certificates are kept in a request database while they are active. This is from the moment they are created until an event occurs that causes them to be deleted. The following table summarizes possible statuses. During the time period when a certificate request is active, it can have only one of the following statuses at a time:
Table 1. Statuses of certificate requests
Status Meaning
Start of changePending ApprovalEnd of change Start of changeThe request requires administrative approval. No action has been taken on the request yet.

If the template that is used to create the certificate request specified an <ADMINNUM> value greater than 1, the request status might remain in Pending Approval state if the required number of individual administrator approvals have yet to be made for this request. If an Approve with Modifications is issued on a request that requires multiple approvals, all prior approvals are nullified and the current approval count for the request is set to 1.

End of change
Approved The administrator explicitly approved the request or it was submitted as an auto-approved certificate request. The actual certificate might or might not have been created.
Completed The certificate has been issued and the requestor has retrieved it. This is a final state.
Preregistered The certificate request is from a preregistered Simple Certificate Enrollment Protocol (SCEP) client.
Rejected The administrator rejected the request, and the requestor has not been informed of this action (because the user has not tried to retrieve the certificate).
Rejected, User notified The administrator rejected the request and the requestor has been informed of this action when attempting to retrieve the certificate. This is a final state.

A request is deleted from the request database when the administrator explicitly deletes it or when the request expires. This expiration time period is configurable and varies depending on whether the request was finalized or not.