To update certificates for protected internal servers
without incurring downtime, renew or obtain a new server
certificate before it expires or otherwise becomes
invalid. Then, import the certificate and private key
onto your
NGFW or
Strata Cloud Manager,
add it to an SSL Inbound Inspection policy rule before
installing the same certificate onto your web server.
Updating your policy rule with a new certificate while
another is active on your web server prepares the
NGFW to decrypt traffic to the server
regardless of the certificate in use.
Configure SSL Inbound
Inspection describes this process
further.