The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Actions for re-signing certificate

Prev Next

Once the Sensor validates the web server certificate, the Sensor uses the trusted certificates to encrypt the SSL session with the client.

  1. Go to Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.

  2. On the Outbound tab, select Re-Signing Certificate tab.

    GUID-DD61046C-49C1-4F5B-9720-8AAC3F1A04BD-low.jpg
  3. To import a trusted certificate:

    1. Click Manage Certificate.

    2. Click Import. The Import Re-Signing Certificate dialog box opens.

      Re-signing_Cert_Import.png
    3. Click Browse.

    4. Select the .p12 file stored in the local system.

    5. Enter the Passphrase for the certificate file.

      This is the phrase (export password) you used for encrypting your PKCS12 file.

    6. Click Import.

      Note

      If you import a custom certificate, the default certificate is removed from the Sensor. If you want to use the default certificate, click the Use Default option to use the default certificate.

  4. To export the public key of the certificate, click Export Public Key.

    You need to export the public key of the Sensor and import it to the browsers in the client systems.

  5. (Optional) Click Use Default.

  6. (Optional) Click Regenerate Default to regenerate the default certificate.

    You can use this option if the certificate you are using has expired.

    To ensure that the Sensors are using the correct certificates, deploy the configuration changes to the Sensor.