The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage SSL certificates

Prev Next

Upload, download, and regenerate SSL certificates and the certificate revocation list (CRL). Schedule updates to the CRL.

If you want to schedule CRL updates, you need a valid URL from a CRL source.

You can apply a certificate from a file, generate a self-signed certificate, generate an authority-signed certificate, or regenerate the default certificate.

  1. From the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png then System Information.

  2. Next to Manage Certificates, click Setup.

  3. Upload a certificate.

    1. Click Upload.

    2. Click OK in the informational pop-up window.

    3. In the Import File pop-up window, click Browse and select the CRT and Key files.

  4. Generate a self-signed certificate.

    1. Under Self-Signed Certificate, click Generate.

    2. Set the key size, location information, and organization information.

    3. Click Save.

  5. Generate an authority-signed certificate.

    1. Under Signed Certificate Request, click Generate.

    2. Set the key size, location information, and organization information.

    3. Click Save.

  6. Regenerate the default Trellix certificates.

    1. Click Regenerate.

    2. Click Yes in the pop-up window.

  7. Expand the Certificate Revocation List menu.

    GUID-DF01E120-C61E-4BEE-9850-25E37A4869F9-low.png
  8. Upload a certificate revocation list (CRL).

    1. Click Upload.

    2. In the Import File pop-up window, browse to the CRL file and select it.

    3. Click Confirm.

  9. Download the CRL.

    1. Click Download.

    2. Select a file location and click and save the file.

  10. Schedule regular updates of the CRL.

    1. Select Set up a retrieval schedule.

    2. Enter the URL of the CRL source.

    3. Set the update frequency.