The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Remove the CA-signed certificate chain

Prev Next

Prerequisites:

You can remove the CA-signed certificate chain only if the following conditions are met:

  • You can remove the certificate chain for the Manager only if all the Sensors managed by the Manager is using self-signed certificate.

  • The active certificate should be changed to self-signed before removing the CA certificate from the Manager.

To remove the certificate chain, perform the following steps:

Steps:

  1. To remove the certificate chain for the Manager, go to Manager → <Root Admin Domain> → Setup → Certificates.

    To remove the certificate chain for the Sensor, go to Devices → <Root Admin Domain> → Devices → <Device Name> → Setup → Trust Certificates.

  2. In the CA-Signed Certificate section, go to Key Size and select the required RSA key size.

    ExportCACertificateKS.png

    Note

    Only certificates with the preferred key size are removed.

  3. Now, go to Other Actions and select Remove Certificate.

    RemoveCACertificate.png

    The CA-signed certificate chain will be removed from the Manager.

    Note

    You must remove the CA-signed certificate chain separately for every Sensor and then have the trust reestablished with the Manager.