Managing certificates

When communicating with the orchestrator, the CPE device checks whether the orchestrator's certificates can be trusted to prevent MITM attacks. By default, the CPE device trusts public certification authorities.

If the orchestrator uses certificates signed by a custom certification authority, you must upload these certificates in the orchestrator web interface and install them on CPE devices. Standalone root certificates as well as certificate chains consisting of a root certificate and multiple intermediate certificates are supported.

30 days before the certificate expires, a notification is displayed when you log into the orchestrator web interface.

The table of certificates is displayed under SD-WAN → Certificates. Information about certificates is displayed in the following columns of the table:

The actions you can perform with the table are described in the Managing solution component tables instructions.

In this section

Uploading a certificate using the orchestrator web interface

Manually installing certificates on CPE devices

Scenario: installing certificates on a CPE device with firmware version 23.07

Exporting a certificate

Deleting certificates

Page top