In the Manager, you can import, re-import, and delete the private SSL certificates and their key of the web servers that you want a specific Sensor to protect. All these actions require a configuration update for the changes to take effect. The Manager stores these keys in an encrypted format and sends them to the corresponding Sensor when you do a configuration update. If a Sensor reboots, it automatically requests the Manager for its SSL keys.
Note
For virtual Sensors in public cloud, you need to complete a signature set push to import the SSL keys to the virtual Sensors.
Note
You need to manage the SSL keys on a per Sensor basis. For example, if there are two different data paths to a server that are protected by two different Sensors, you must import the SSL key of the server separately for both the Sensors. In case of failover Sensors, the SSL keys on the primary is automatically copied over to the secondary.
Note
If you upgrade the capacity of a stack of NS9500 Sensors, you need to re-import the SSL keys.