Working with tags in the certificate inventory
Table of Contents
Expand all | Collapse all
-
- Activate Next-Generation Trust Security
-
-
- Configure AWS connection
- Configure Azure Key Vault connection
-
- Workload Identity Federation authentication
- Workload Identity Federation - Azure Identity Provider authentication
- Next-Gen Trust Security Generated Key authentication
- User permissions
- Workload Identity Federation authentication
- Next-Gen Trust Security Generated Key authentication
- User permissions
- Supported OIDC claims
-
-
-
-
- Create an F5 BIG-IP LTM machine
- Create a Microsoft Azure Private Key Vault machine
- Create a Microsoft IIS machine
- Create a Microsoft Windows (PowerShell) machine
- Create a Microsoft SQL Server machine
- Create a Common KeyStore machine
- Create a Citrix ADC machine
- Create an Imperva WAF machine
- Create a VMware NSX Advanced Load Balancer (AVI) machine
- Create an A10 Thunder ADC machine
- Create a Cloudflare machine
- Create Kemp Virtual LoadMaster machine
- Create a Palo Alto Panorama machine
-
- Provision to an F5 BIG-IP LTM
- Provision to a Microsoft Azure Private Key Vault
- Provision to Microsoft IIS
- Provision to Microsoft Windows (PowerShell)
- Provision to Microsoft SQL Server
- Provision to a Common KeyStore
- Provision to a Citrix ADC
- Provision to an Imperva WAF
- Provision to VMware NSX Advanced Load Balancer (AVI)
- Provision to an A10 Thunder ADC
- Provision to Cloudflare
- Provision to a Kemp Virtual LoadMaster
- Provision to Palo Alto Panorama
-
-
- 47-Day Validity Readiness TLS Certificates dashboard
- About the Certificate Inventory
- Managing certificate lifecycle settings
- Reissuing certificates in Next-Gen Trust Security
- Downloading certificates, certificate chains, and keystores
- Retiring, recovering, and deleting certificates
- Finding certificates in the certificate inventory
- Importing certificates from a CA using EJBCA
- Notification Center overview
- Domain-based validation for external emails
- Managing user accounts
- Troubleshooting
Working with tags in the certificate inventory
Tagging helps you group and manage related certificates. You can centrally manage tags on the Configurations > Tags page. You can also assign, modify, and clear tags directly from the certificate inventory.
Assign tags to existing certificates
- Open the certificate inventory by going to Inventory > Certificates.
- Select the certificates you want to tag.
- In the local menu bar, click Tag > Add Tags.
- Click in the Tags field and select existing tags, or enter a new tag or key:value pair.Note (When creating new tags):
- Creating a key:value pair also creates a standalone tag for the key value.
- Tag names cannot be changed or deleted using the UI after creation.
- You can create multiple values for the same key.
- Optional: Select Replace current tag assignments to replace existing tags.
- Click Save.
After tags are applied, they appear in the Tags section of the certificate details and in the Tags column of the inventory. Tags are retained when you renew a certificate.
Change tags on a certificate
You can update tags for a single certificate or for multiple certificates at once.
Change tags on a single certificate
- Open the certificate inventory by going to Inventory > Certificates.
- Select the certificate whose tags you want to change.
- In the local menu bar, click Tag > Add Tags.
- Remove existing tags by selecting the delete icon next to each tag.
- Add or update tag assignments. Keep in mind that a certificate can have a maximum of 20 tags.
- Click Save.
Modify tag values on a single certificate
- Open the certificate inventory by going to Inventory > Certificates.
- Select the certificate whose tag values you want to edit.
- In the local menu bar, click Tags > Edit Tags.
- Edit the tag values.
- Click Save.
Change tags on multiple certificates
- Open the certificate inventory by going to Inventory > Certificates.
- Select the certificates you want to update.
- In the local menu bar, click Tag > Add Tags.
- Add or select tag assignments.
- Optional: Select Replace current tags to overwrite existing tags.Note:
- If adding tags causes a certificate to exceed the 20-tag limit, that certificate is skipped.
- If all selected certificates exceed the limit, the operation fails.
- Click Save.
Clear all tags from certificates
- Open the certificate inventory by going to Inventory > Certificates.
- Select the certificates whose tags you want to clear.
- In the local menu bar, click Tag > Clear Tags.
- Confirm by clicking Clear.
Clearing tags removes all tag assignments from the selected certificates but does not delete the tags themselves. Tags remain available to be reused.
Filter certificates by tags
After assigning tags, you can filter the certificate inventory by tag. Select Tag from the Add Criteria dropdown, and then choose the tags to filter on.
Next-Gen Trust Security includes a system tag named Venafi, which cannot be modified, assigned, removed, or deleted.