: Adding a Certificate Authority
Focus
Focus

Adding a Certificate Authority

Table of Contents

Adding a Certificate Authority

When you add a certificate authority (CA) to Next-Gen Trust Security, you create a connection between Next-Gen Trust Security and that CA. That connection enables Next-Gen Trust Security to manage certificate life-cycles.
Next-Gen Trust Security can connect to both external and internal CAs, in addition to its own built-in CA.

Before You Begin

Before setting up your CA, review the following:
  • If you plan to use paid public trust CAs (like DigiCert, excluding free ones like Let's Encrypt), an enterprise CA account is required. Make sure you have a billing setup for pre-purchasing certificate units or for post-use billing. This is simply because our platform doesn't support purchasing individual certificates with a credit card for each transaction.
  • Have your CA authentication credentials ready before you can configure and test issuance. Each CA provider has its own authentication methodology.
  • Make sure you have the Superuser role in the parent TSG to add new CAs.
  • Note: Certificate Authorities are parent TSG resources. Only users in the parent TSG can create or configure CA connections. Child TSGs can use CAs for certificate issuance through shared Issuing Templates.
  • To take advantage of high availability for certificate issuance and management, select a primary VSatellite that belongs to a high availability group. The system will automatically choose a healthy VSatellite from that group to initiate operations. This helps ensure reliability even if one VSatellite becomes temporarily unavailable.

Getting Started

Select your CA below for a detailed how-to.

Custom Certificate Authority