: Provision certificates to machines
Focus
Focus

Provision certificates to machines

Table of Contents

Provision certificates to machines

Next-Gen Trust Security can provision certificates directly to machine keystores. If you haven’t created the machine yet, start by creating a new machine. Otherwise, follow the steps below.

Before you begin

  • The certificate you want to provision must already exist in the Next-Gen Trust Security Certificates inventory and include a private key.
  • The machine must already be created in Next-Gen Trust Security. If it isn’t, see Create a new machine.
Note: Only certificates with an associated private key can be provisioned. Certificates must have a status of New or Installed. Provisioning fails for certificates in other states.
Note (How renewals work during scheduled provisioning):When a certificate is renewed, Next-Gen Trust Security updates the machine’s Installations list and sets the status to New.Running certificate discovery keeps the status as New, ensuring the renewed certificate remains queued for provisioning.During the next scheduled provisioning run, Next-Gen Trust Security provisions the renewed certificate to the machine, replacing the previous version.

Batch provisioning

Batch provisioning provisions all certificate installations for a machine in a single operation.
  1. In the Next-Gen Trust Security toolbar, click Installations, then select Machines.
  2. Select the machine you want to provision.
  3. Click Provision Now.
  4. A message below the machine name shows when provisioning starts. Refresh the page to see completion status.
Note: You can click Abort Provisioning to stop the process before completion. Aborting may take a short time to finalize.

Set up a machine provisioning schedule

  1. In the Next-Gen Trust Security toolbar, click Installations, then select Machines.
  2. Select the machine you want to configure.
  3. Click the Provisioning tab.
  4. Enable the Machine Provisioning Schedule toggle.
  5. Under Repeat every, choose Daily, Weekly, or Monthly, then select a time.
  6. Click Save.
Note: Times are shown in UTC.
Note: Scheduled provisioning works best when used with application auto-renewal. Certificates are provisioned only when a certificate is queued for deployment, allowing renewals to be installed in a controlled time window.