Change the Purpose of an Uploaded CA Certificate
Certificates must have at least one purpose selected.
Deselecting a purpose is the equivalent of deleting a certificate that is used for that purpose. For the effects of doing so, see Delete a CA Certificate, below.
If you enable "ZTA enrollment", a new configuration file is generated after you click Save. You must download and distribute this file to user devices that will depend on this certificate for Zero Trust Access certificate-based enrollment.
If your organization has a Cisco-provided CA certificate intended to authenticate VPN connections: This certificate cannot be used for Zero Trust Access enrollment and the option is not available for that certificate.
To change the purpose of a CA certificate:
- Navigate to Secure > Certificates > Client authentication.
- Click the pencil icon to modify the certificate.
- Click Save.
- If you enabled ZTA enrollment, download and distribute the newly generated configuration file to user devices.