The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing an SSL interception CA certificate using the CLI

Prev Next

Use the commands in this section to import the trusted and untrusted SSL CA certificates.

Important

You must import the trusted and untrusted SSL interception CA certificates separately.

To import an SSL interception CA certificate:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Import the certificate.

    hostname (config) # crypto certificate name <certificateName> public-cert pem "<pemString>" [comment"<comment"]

    where:

    • <certificateName> can be a unique name of your choice. For example, you can name the trusted SSL interception CA certificate ssl-proxy-trusted. You can name the untrusted SSL interception CA certificate ssl-proxy-untrusted.

    • <pemString> is the public certificate Privacy Enhanced Email (PEM) string. For details about how to format the PEM string, see Configuring SSL interception CA certificates.

    • <comment> is the text about the certificate. For details about how to add a comment, see Configuring SSL interception CA certificates.

  3. Import the private key.

    hostname (config) # crypto certificate name <certificateName> private-key pem"<pemString>"

    where:

    • <certificateName> can be a unique name of your choice. For example, you can name the trusted SSL interception CA certificate ssl-proxy-trusted. You can name the untrusted SSL certificate ssl-proxy-untrusted.

    • <pemString> is the private key PEM string. For details about how to format the PEM string, see Configuring SSL interception CA certificates.

    (Optional) Import the private key with secure echo, so asterisks are displayed instead of the PEM string characters.

    hostname (config) # crypto certificate name <certificateName> prompt-private-key
  4. Verify that the SSL interception CA certificate has been imported.

    hostname (config) # show crypto certificate name <certificateName>
  5. Save your changes.

    hostname (config) # write memory