Cheat Sheet: Certificate Management with Next-Gen Trust Security
Checklist for getting started with Next-Gen Trust Security certificate management in
Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
|
|
- Secure-Flex Credits
- Appropriate role for the operation (see RBAC section below)
|
Prerequisites Checklist
Before managing certificates through Next-Gen Trust Security in Strata Cloud Manager:
Certificate Management Workflow
Step 1: Access Network Trust Security
Step 2: Manage Certificates
- Bring certificates under Next-Gen Trust Security management
- Click Manage for individual certificates or Manage All for bulk operations
- Managed certificates appear in Next-Gen Trust Security certificate inventory
- Note: Managed certificates count against your license; unmanaged certificates do not
- See Manage Certificates in Next-Gen Trust Security
Step 3: Renew Certificates
- Click Renew for managed certificates needing renewal
- Next-Gen Trust Security generates new certificate using issuing template
- Renewed certificate imports back to Strata Cloud Manager
- Push the updated configuration to your firewalls to complete the update - see Push Config
- See Renew Certificates Using Next-Gen Trust Security
RBAC Permissions
Users need one of these roles for Strata Cloud Manager Shared Services:
| Role | View Certificates | Manage Certificates | Renew Certificates |
| Superuser | ✓ | ✓ | ✓ |
| Security Administrator | ✓ | ✓ | ✓ |
| Network Administrator | ✓ | — | — |
| View Only Administrator | ✓ | — | — |
| Tier 1 Support | ✓ | — | — |
| Tier 2 Support | ✓ | — | — |
Certificate Filtering
The following certificate types are not synced to Network Trust Security:
- Certificates in subscribed snippets
- GP_Log_Certificate (system-managed)
- Certificate signing requests (CSRs)
- CA certificates
- Certificates used in decryption rules
Known Issues
Certificate name length limitation: Certificates with names longer than 31 characters do not sync to Network Trust Security. Rename certificates to 31 characters or fewer before they sync. This limitation will be resolved in a future release.