The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

importcacertfile

Prev Next

This command imports CA cert file from the configured SCP server to the Sensor. The CA file should be in Base64 encoded format (such as .pem, .cer, and .crt).

The uploaded file will override any pre-existing cert store and it will be persisted across reboots. Different cert stores are maintained for public and private GTI. CA cert store for the public GTI gets pushed from the Manager to the Sensor when you establish trust between the Manager-Sensor. For private GTI, however, the CA cert store should use importcacertfile command to import it to the Sensor.

Note

The CLI command resetconfig removes both public and private cert stores from the Sensor.

Syntax:

importcacertfile scp <public|pvt> <filepath>

Parameter

Description

public

CA certificate file for public server

pvt

CA certificate file for private server

<filepath>

Filepath of the CA certificate file in the SCP server

Sample output:

importcacertfile scp pvt/home/test/my-ca-bundle.cer

Applicable to:

NS-series and Virtual IPS Sensors