Renew expiring certificates using Next-Gen Trust Security with enterprise-approved
certificate authorities.
| Where Can I Use This? | What Do I Need? |
|
|
- Secure-Flex Credits
- Superuser role for Strata Cloud Manager Shared Services
- PKI administrator must configure issuing templates in the Next-Gen Trust Security console and link them to the NGFW application - see Configure a Certificate Authority and Get Started with Integrations
- Certificate must be in Managed status
|
Certificate renewal through Next-Gen Trust Security generates new certificates using enterprise-approved certificate authorities and cryptographic settings. When you initiate renewal from the Network Trust Security page in Strata Cloud Manager, Next-Gen Trust Security creates a new private key and certificate signing request (CSR) based on your issuing template settings, submits the CSR to a certificate authority, and imports the renewed certificate with its private key back into Strata Cloud Manager. Only managed certificates can be renewed through Next-Gen Trust Security.
Your PKI administrator must configure issuing templates in the Next-Gen Trust Security console and link them to the NGFW application. Issuing templates are policies that define cryptographic standards for certificate generation, including key algorithm and length, allowed Subject and SANs, certificate validity period, and extended key usage fields.