Sign in to Next-Gen Trust Security.
In the menu bar, click Configurations > Certificate Policies > Certificate Auto-Renewal and Provisioning.
Enable Enable auto-renewal.
When enabled, certificates that are eligible for auto-renewal will be automatically renewed before they expire.
In the Set a global window field, specify the number of days before expiration when certificates become eligible for renewal.
For example, if you set the window to 31 days, all eligible certificates within 31 days of expiration will be renewed and provisioned during the next auto-renewal run.
From the Set a default issuing template dropdown, select the issuing template to be used when auto-renewing certificates.
Select the default issuing template that should be used for certificate renewals.
(Optional) Enable Automatically provision renewed certificates.
When enabled, renewed certificates will be automatically provisioned to their target locations (machine or cloud keystores).
Review the Current auto-renewal status to see whether the Automated Secure Keypair service is active.
Click Save.
(Optional) Click Run Now to immediately renew and provision eligible certificates without waiting for the next scheduled daily run.
After you complete these steps, Next-Gen Trust Security automatically renews eligible certificates based on the configured settings.