The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Re-signing Certificate

Prev Next

The Re-Signing Certificate is used by the Sensor to substitute the server's certificate when establishing a session with the client. The Sensor uses this certificate when responding to the client's request. After the client sends a request, the Sensor receives the public key and the certificate from the web server. The Sensor then validates the certificate by comparing it with the list of trusted certificates available in the trusted CA list. After the Sensor validates the server certificate, it re-signs the certificate using its own certificate before sending it back to the client. This allows the Sensor to decrypt the traffic between the client and server. You can configure your own certificate on the Re-Signing Certificate tab. It can be a customized certificate issued by the CA.

Note

  • Re-Signing Certificate can be managed only at the domain level. From the 11.1 Update 8 release, certificates up to 4096-bit are supported.

  • The re-signing CA certificate must be created for server authentication and added to the browser as a trusted authority without purpose limitations.

Note

You must re-import the Re-Signing Certificate after adding a new Sensor.

Note

For a stack of NS9500 Sensors, you must re-import the Re-Signing Certificate after a capacity upgrade from 40 Gbps or 60 Gbps to 100 Gbps.

When you enable outbound SSL decryption for the first time, the default re-signing certificate provided with the Manager is displayed. You cannot enable the outbound SSL decryption feature with a customized re-signing certificate when you enable the feature for the first time. You can import the customized certificate later.