Manage certificates
Last updated November 6th, 2025
Manage already-issued external certificates on the Certificates page for enhanced security (Connection and security > Certificates). You can upload certificates — such as for Wi-Fi, VPN, and APNs — as well as view details, edit, and delete certificates.
To see details of an existing certificate, such as the certificate purpose and expiration date, click the corresponding link under CERTIFICATE NAME.
Upload a certificate
Complete the following steps to upload a certificate:
- Open the Certificates page and click UPLOAD CERTIFICATE.
- On the Upload certificate page, enter the following information:
- Certificate name (alias) — Assign a unique name for each certificate.
- Purpose — Select a purpose for the certificate.
- Wi-Fi — Authorizes connecting with an Access Point (AP) for Wi-Fi.
- VPN — Authorizes encrypted VPN communication when registering Knox Manage on devices.
- CA Cert — Authorizes communication with a registered Certificate Authority (CA) based on the user’s public key.
- Code Signing Certificate — Verifies code authenticity, ensures integrity, and protects against malicious code.
- Syslog — Logs system events, centralizes monitoring, and detects security threats.
- Identity provider — Authenticates users, authorizes access, and enables Single Sign-On (SSO).
- Type — Select a type for the certificate.
- User — Certificate issued for general purposes, such as to authenticate devices or applications.
- Server — Server certificate for general purposes.
- Root — Highest level of certificate that identifies the Root CA.
- File type — Click the upload icon and select a certificate file in P12, PFX, CER, DER, CRT or PEM format.
- P12, PFX — Used for private keys and certificates.
- CER, DER, CRT, PEM — Used for public keys and certificates.
- Description — Enter a description for the certificate.
- Click UPLOAD. The certificate will be registered with Knox Manage.
Edit a certificate
You can edit certificates as follows:
-
Open the Certificates page.
-
Select the certificate you want to modify, then click ACTIONS > Edit certificate.
-
On the Edit certificate page, edit certificate information as needed.
The Purpose and Type values of external certificates can’t be modified.
-
Click Save.
Delete a certificate
To delete a certificate, complete the following steps:
- Open the Certificates page.
- Select the certificate you want to delete, then click ACTIONS > Delete certificate.
- In the Delete certificate window, click DELETE.
This document was updated for the Knox cloud services 25.11 UAT.
On this tab
Upload new and manage already-issued external certificates on the UPLOADED CERTIFICATES tab of the Certificates page for enhanced security (Connection and security > Certificates). You can upload certificates — such as for Wi-Fi, VPN, and APNs — as well as view details, edit, and delete certificates.
Add and manage templates on the TEMPLATES AND CA tab of the Certificates page.
To see details of an existing certificate, click the corresponding link under the CERTIFICATE NAME or TEMPLATE NAME column.
To learn how to connect to and manage a certificate authority (CA), see Manage certificate authorities.
Upload a certificate
Complete the following steps to upload a certificate:
- Open the Certificates page and click UPLOAD CERTIFICATE.
- On the Upload certificate page, enter the following information:
- Certificate name (alias) — Assign a unique name for each certificate.
- Purpose — Select a purpose for the certificate.
- Wi-Fi — Authorizes connecting with an Access Point (AP) for Wi-Fi.
- VPN — Authorizes encrypted VPN communication when registering Knox Manage on devices.
- CA Cert — Authorizes communication with a registered Certificate Authority (CA) based on the user’s public key.
- Code Signing Certificate — Verifies code authenticity, ensures integrity, and protects against malicious code.
- Syslog — Logs system events, centralizes monitoring, and detects security threats.
- Identity provider — Authenticates users, authorizes access, and enables Single Sign-On (SSO).
- Type — Select a type for the certificate.
- User — Certificate issued for general purposes, such as to authenticate devices or applications.
- Server — Server certificate for general purposes.
- Root — Highest level of certificate that identifies the Root CA.
- File type — Click the upload icon and select a certificate file in P12, PFX, CER, DER, CRT or PEM format.
- P12, PFX — Used for private keys and certificates.
- CER, DER, CRT, PEM — Used for public keys and certificates.
- Description — Enter a description for the certificate.
- Click UPLOAD. The certificate will be registered with Knox Manage.
Edit a certificate
You can edit certificates as follows:
-
Open the Certificates page.
-
Select the certificate you want to modify, then click ACTIONS > Edit certificate.
-
On the Edit certificate page, edit certificate information as needed.
The Purpose and Type values of external certificates can’t be modified.
-
Click Save.
Delete a certificate
To delete a certificate, complete the following steps:
- Open the Certificates page.
- Select the certificate you want to delete, then click ACTIONS > Delete certificate.
- In the Delete certificate window, click DELETE.
Upload a template
The Certificate Authority (CA) server manages certificates through certificate templates. You can add as many templates as you need, and modify them to standardize and simplify the process of issuing certificates.
To upload a template:
-
On the Certificates page, go to the TEMPLATES AND CA tab.
-
Click ADD TEMPLATE. The Add template page opens.
-
Enter the following information:
-
Template name — Assign a unique name for the certificate template.
-
Description — Enter a description for the certificate template.
-
Purpose — Select a purpose for the certificate.
Only Wi-Fi is currently supported.
-
CA name — Assign a unique name for the certificate authority.
-
Subject name — Enter a subject name in CN = {Subject name value} format. Alternatively, click Lookup to open the Select Lookup Item dialog and select an item.
-
SAN type — Select a SAN type, and then enter the SAN value. Click to add.
-
-
Click ADD.
To view details of a template, click on the name of a template under the TEMPLATE NAME column. The sliding details panel displays with details like template purpose, SAN type, and more.
Edit a template
To edit a template:
-
On the Certificates page, go to the TEMPLATES AND CA tab.
-
Select the checkbox of the template you want to edit, then click ACTIONS > Edit template.
-
Edit the details as required.
-
Click SAVE.
Delete a template
To delete a template:
-
On the Certificates page, go to the TEMPLATES AND CA tab.
-
Select one or more checkbox of the templates you want to delete, then click ACTIONS > Delete template(s). The Delete template dialog displays.
-
Click DELETE to confirm your intent to delete the template.
Is this page helpful?
Thank you for your feedback!