Tagging Certificates
Table of Contents
Expand all | Collapse all
-
- Activate Next-Generation Trust Security
-
-
- Configure Akamai Connection
- Configure AWS Connection
- Configure Azure Key Vault Connection
-
- Workload Identity Federation Authentication
- Workload Identity Federation - Azure Identity Provider Authentication
- Next-Gen Trust Security Generated Key Authentication
- User Permissions
- Workload Identity Federation Authentication
- Next-Gen Trust Security Generated Key Authentication
- User Permissions
- Supported OIDC Claims
-
-
-
- Working with the Built-in CA
- Add AWS Public CA
- Add AWS Private CA
- Add DigiCert One Certificate Authority
- Add Entrust
- Add GlobalSign Atlas
- Add GlobalSign MSSL
- Add GoDaddy
- Add Google Cloud Private CA
- Add a HID PKIaaS CA
- Add Certificate Manager - Self-Hosted
- Set Up an OpenSSL Certificate Authority Connector
- Create a Sectigo Certificate Manager Certificate Authority
- Add Zero Touch PKI
- Set Up Certificate Expiration Notifications
- Using a Custom DNS Provider
-
-
-
-
- Create an F5 BIG-IP LTM Machine
- Create a Microsoft Azure Private Key Vault Machine
- Create a Microsoft Azure Application Registration Machine
- Create a Microsoft IIS Machine
- Create a Microsoft Windows (PowerShell) Machine
- Create a Microsoft SQL Server Machine
- Create a Common KeyStore Machine
- Create a Citrix ADC Machine
- Create an Imperva WAF Machine
- Create a VMware NSX Advanced Load Balancer (AVI) Machine
- Create an A10 Thunder ADC Machine
- Create a Cloudflare Machine
- Create Kemp Virtual LoadMaster Machine
- Create a Palo Alto Networks Panorama Machine
- Create a Radware Alteon Machine
-
- Provision to an F5 BIG-IP LTM
- Provision to a Microsoft Azure Private Key Vault
- Provision to Microsoft IIS
- Provision to Microsoft Windows (PowerShell)
- Provision to Microsoft SQL Server
- Provision to a Common KeyStore
- Provision to a Citrix ADC
- Provision to an Imperva WAF
- Provision to VMware NSX Advanced Load Balancer (AVI)
- Provision to an A10 Thunder ADC
- Provision to Cloudflare
- Provision to a Kemp Virtual LoadMaster
- Provision to Palo Alto Networks Panorama
- Provision Certificates to Radware Alteon
-
-
- 47-Day Validity Readiness TLS Certificates
- About the Certificate Inventory
- Managing Certificate Lifecycle Settings
- Reissuing Certificates in Next-Gen Trust Security
- Downloading Certificates, Certificate Chains, and Keystores
- Retiring, Recovering, and Deleting Certificates
- Finding Certificates in the Certificate Inventory
- Importing Certificates from DigiCert
- Importing Certificates from EJBCA
- Importing Certificates from GlobalSign Atlas
- Importing Certificates from GlobalSign MSSL
-
- Create a Workload Identity Management or Discovery Agent Built-in Account
- Create an OCI Registry Built-in Account
- Create a Certificate Manager - Self-Hosted Built-in Account
- Create a Scanafi Built-in Account
- Toggling a Built-in Account On or Off
- Editing Built-in Accounts
- Deleting Existing Built-in Accounts
- Renew Existing Built-in Accounts
- Troubleshooting
Tagging Certificates
In Next-Gen Trust Security, tags are user-defined keys or key:value pairs that can be assigned to certificates. Tags allow you to add customized meta information to certificates beyond just the certificate properties. This gives you more insight and control in managing your certificate inventory, and it provides the ability for 3rd party integrations to act based on the presence or absence of tags.
Example: One example use of tags might be to use a team-name:purpose tagging convention. Following that convention, you might have tags such as infrastructure:loadbalancer and infrastructure:database.
After you assign tags to certificates, you can filter your certificate inventory by these tags. This helps you quickly manage your inventory and organize certificate-related work.
You can add tags to a certificate request, and you can add or edit tags for existing certificates. Administrators can centrally manage tags using the Configurations > Tags page.
Before You Begin
- Users with the Superuser roles can create, assign, and remove tags on certificates they have access to. Users with the Superuser roles can also filter the certificate inventory using tags. Other tagging tasks must be performed by an administrator.
- Know at least one of the keys or key:value pairs you want to create as a tag.
- Creating a key:value pair also creates a standalone tag for the key value.
- A certificate can have a maximum of 20 tags assigned to it.
Managing Tags Centrally
Administrators can use the Configurations > Tags page to view and manage all tags in the system. Each tag lists its keys and values, along with the number of active (non-retired) certificates using that tag.
Select a value in the Active Certificates column to view those certificates in the certificate inventory.
If you have many tags, use the Search box to locate specific tags.
To create or delete tags, see Editing tags.
Assigning Tags to Existing Certificates
- Sign in to Next-Gen Trust Security.
- Click Insights > Certificate Inventory > Certificates.
- In the certificate inventory, select the certificates you want to tag.
- In the local menu bar, click Tag > Add Tags.
- Click in the Tags field and select existing tags, or enter a new tag or key:value pair.Note (When creating new tags):
- Creating a key:value pair also creates a standalone tag for the key value.
- Once created, tag names can't be changed or deleted using the UI.
- You can create multiple values for the same key.
- Optional: To replace existing tags, select Replace current tag assignments.
- Click Save.
After tags are applied, they appear in the Tags section of the certificate details and in the Tags column of the inventory. Tags are retained when you renew a certificate.
Changing Tags on a Certificate
Changing Tags on a Single Certificate
- Click Insights > Certificate Inventory > Certificates.
- Select the certificate whose tags you want to change.
- In the local menu bar, click Tag > Add Tags.
- Remove existing tags by selecting the delete icon next to each tag.
- Add or modify tag assignments.
- Click Save.
Changing Tags on Multiple Certificates
- Click Insights > Certificate Inventory > Certificates.
- Select the certificates you want to update.
- In the local menu bar, click Tag > Add Tags.
- Add or select tag assignments.
- Optional: Select Replace current tag assignments to overwrite existing tags.Note:
- If adding tags causes a certificate to exceed the 20-tag limit, that certificate is skipped.
- If all selected certificates exceed the limit, the operation fails.
- Click Save.
Clearing All Tags from a Certificate
- Click Insights > Certificate Inventory > Certificates.
- Select the certificates whose tags you want to clear.
- In the local menu bar, click Tag > Clear Tags.
- Confirm by clicking Clear.
Clearing tags removes all tag assignments from the selected certificates but doesn't delete the tags themselves.
Filtering Certificates by Tags
After assigning tags, you can filter the certificate inventory by tag. Select Tag from the Add Criteria dropdown and choose the tags to filter on.
Next-Gen Trust Security includes a system tag named Venafi, which can't be modified or removed.
Viewing Tagging Events
Tagging actions appear in the Next-Gen Trust Security event log. Use filters to view specific tagging-related events.
| Tagging event | Add Criteria | Event |
|---|---|---|
| New tag created | Event | Tags Created |
| Tag removed from system | Event | Tags Deleted |
| All tags removed from a certificate | Event | Certificate All Tags Deleted |
| Tags replaced on a certificate | Event | Certificate Tags Replaced |
| Tag added to a certificate | Event | Certificate Tags Added |
| Tag added to a certificate request | Event | Tags Assignment on Certificate Request |