# CertificateAuthorityDeletion

**URL:** <https://openziti.discourse.group/t/certificateauthoritydeletion/3411>\
**Category:** General Questions\
**Created:** [November 11, 2024, 11:18am UTC](https://openziti.discourse.group/t/certificateauthoritydeletion/3411 "2024-11-11T11:18:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![devawasthi](https://avatars.discourse-cdn.com/v4/letter/d/41988e/32.png) [@devawasthi](https://openziti.discourse.group/u/devawasthi)\
**Post date:** [November 11, 2024, 11:18am UTC](https://openziti.discourse.group/t/certificateauthoritydeletion/3411/1 "2024-11-11T11:18:48Z")

</div>

Hi, I have a question regarding identities linked to a Certificate Authority (CA). If I delete this CA, OpenZiti deletes it —so will those linked identities continue to function? If they won’t, could you explain why the deletion of a CA is permitted in this case?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [November 12, 2024, 12:14pm UTC](https://openziti.discourse.group/t/certificateauthoritydeletion/3411/2 "2024-11-12T12:14:08Z")

</div>

The identities will not continue to function if you delete the CA. It's allowed because there's no way for OpenZiti to know what identities (if any) any given CA is being used to authenticate with.
