Change the Purpose of an Uploaded CA Certificate

Certificates must have at least one purpose selected.

Deselecting a purpose is the equivalent of deleting a certificate that is used for that purpose. For the effects of doing so, see Delete a CA Certificate, below.

If you enable "ZTA enrollment", a new configuration file is generated after you click Save. You must download and distribute this file to user devices that will depend on this certificate for Zero Trust Access certificate-based enrollment.

If your organization has a Cisco-provided CA certificate intended to authenticate VPN connections: This certificate cannot be used for Zero Trust Access enrollment and the option is not available for that certificate.

To change the purpose of a CA certificate:

  1. Navigate to Secure > Certificates > Client authentication.
  2. Click the pencil icon to modify the certificate.
  3. Click Save.
  4. If you enabled ZTA enrollment, download and distribute the newly generated configuration file to user devices.