Software Secure Access
Activity Manage

Step 2 - Upload or choose a CA certificate

User endpoint devices present an identity certificate when enrolling and renewing enrollment.

Secure Access must hold the certificate that verifies these user identity certificates.

You can upload a new certificate or choose an already-uploaded certificate. Zero Trust Access enrollment can use the same certificate that validates identity certificates for VPN connections, or use a different certificate for zero trust enrollment. You must specify the purpose or purposes of each certificate during upload. You can modify the purpose later. Uploads must include the intermediate certificates required to complete the chain of trust.

To upload the certificate:

  1. Navigate to a page where you can upload CA certificates for enrollment.

    You can upload CA certificates for this purpose from either of two places in Secure Access. The result is identical.

    1. Option 1: Upload certificates to the Enrollment Methods page, which also includes the link to download the new configuration file that is generated after you upload a CA certificate.
      1. Navigate to Connect > End User Connectivity.
      2. Click the Zero Trust Access tab.
      3. In the Enrollment Methods section, click Manage.
      4. Click Upload a CA Certificate.
      5. Complete the form as described in Manage CA Certificates for VPN Connections and Zero Trust Access Enrollment.
    2. Option 2: Upload certificates to the client authentication certificates page:

      See Manage CA Certificates for VPN Connections and Zero Trust Access Enrollment.