The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import the CA-signed certificate

Prev Next

To import the CA-signed certificate chain, perform the following steps:

  1. To import the CA-signed certificate chain for the Manager, go to Manager → <Root Admin Domain> → Setup → Certificates.

    To import the CA-signed certificate chain for the Sensor, go to Devices → <Root Admin Domain> → Devices → <Device Name> → Setup → Trust Certificates.

  2. In the CA-Signed Certificate section, click Import Certificate.

    GUID-4FEECDE9-0552-4C57-B2E4-F0025F6EB7AD-low.png

    Note

    If the Manager or Sensor contains both 2048-bit and 4096-bit CA-signed certificates, the Import Certificate option will be disabled.

    Note

    The Import Certificate button becomes active only after you generate and export the CSR.

  3. In the Import Certificate dialog box, click Browse.

    GUID-D02D3058-6B98-40D7-8433-EF8BCAFE3C8C-low.png
  4. Browse to the directory that contains the certificate chain, click Open.

    Note

    • The CA-signed certificate chain should be in .pem format.

    • From the 11.1 Minor 6 release, the CA certificate file size has been increased to support more than 2046 bytes.

  5. Click Import for the manager and each sensor connected to the manager.

    The Manager validates the CA-signed certificate chain with the CSR. If the validation is successful, the certificate chain details are displayed in the CA-Signed Certificate section.