Replace an internal certificate (decrypt - replace cert only)

Replace expiring internal certificates in decryption policies to maintain secure encrypted traffic inspection capabilities.

This task discusses how to replace the internal certificate used in an incoming decryption rule using the Cloud-Delivered Firewall Management Center.

You can also replace the certificate using the API as discussed in Cloud-Delivered Firewall Management Center REST API Quick Start Guide.

The system indicates that an internal certificate is expiring when today's date is within 30 days of its expiration date. The following figure shows an example.

The figure illustrates the process of replacing an internal certificate using the Decrypt - Replace Cert action in a policy, highlighting the necessary steps and options available in the system.

Before you begin

You must choose the Decrypt - Replace Cert decryption rule action in one of these ways:

  • In a rule-based decryption policy by clicking the action from the rule's Action list.

  • Create a standard decryption policy, which always uses the Decrypt - Replace Cert rule action.

Follow these steps to replace an internal certificate using the Decrypt - Replace Cert rule action:

Procedure


Step 1

Log in to Security Cloud Control if you haven't already done so.

Step 2

Click Firewall.

Step 3

Click Administration > (name of Cloud-Delivered Firewall Management Center) > Objects > PKI > Internal Certs.

Step 4

Locate the internal certificate that is expired or expiring (for example, an expired certificate is indicated by The diagram illustrates the process of replacing an internal certificate, highlighting the steps involved in decrypting and replacing the certificate without affecting system functionality.).

Step 5

Click Edit (edit icon).

Step 6

Click Update Certificate as this figure shows.

The internal certificate replacement process is illustrated, showing the successful update of the decryption policy to inspect encrypted traffic with the new certificate.

Step 7

Enter the requested information; see Upload an internal certificate for inbound protection for more information.

Step 8

Follow the prompts on your screen to complete the action.