Skip to main content

Certificates

The Certificates screen is your inventory of every managed identity: what it is, which profile issued it, which algorithm it uses, how it is deployed and when it expires.

ConsoleCertificates

What it's for​

  • Find a certificate by name, serial number or profile.
  • Filter the inventory by signature algorithm and lifecycle state.
  • Start a new certificate request.
  • Revoke a certificate immediately, optionally failing over to a healthy standby first.

What you see​

Certificates inventory with a search box, algorithm and lifecycle filters, and a table of managed identities with Revoke buttons
The certificates inventory.

The card title shows the total, for example 12 managed identities, and a Request certificate button.

Filters​

ControlWhat it does
Search names, serials, profiles…Matches the identity (endpoint ID), the profile ID or the active certificate's serial number. Not case-sensitive.
AlgorithmAll algorithms, or one of the algorithms actually present in your inventory, for example ECDSA P-256, ECDSA P-384, RSA-PSS 3072 or Hybrid P-384 + ML-DSA-65.
Lifecycle stateAll lifecycle states, Serving, Staged, Draining or Revoked. Filters on the state of the active slot.

The algorithm shown for each certificate is the one recorded on the transaction that issued its active certificate. A certificate with no matching transaction shows — and only appears under All algorithms.

If nothing matches, the table shows No managed identities match these filters.

Table columns​

ColumnContent
IdentityThe endpoint identity (the spiffe:// prefix is hidden) and the active certificate's serial number.
ProfileThe workload profile that governs the certificate.
AlgorithmSignature algorithm, or —.
DeploymentRotation mode: dual slot or in place.
ExpiryExpiry date of the active certificate, or —.
StatusLifecycle state of the active slot: serving, staged, draining, retired, revoked, or pending when there is no active certificate. Shown green when the active certificate reports healthy.
ActionRevoke. Disabled when there is no active certificate or it is already revoked.

Request a certificate​

Certificates are not issued from a form in the console. Workloads request them locally, through a Mesh Node, so that both trust domains can approve the exact request. Request certificate shows you where to go.

Request a managed identity dialog with two options and a local CLI example
The Request a managed identity dialog.
  1. Select Request certificate.
  2. In Request a managed identity, choose a path:
    • Local Mesh Node: Use ACME, the CLI, SDK, or SPIFFE Workload API. Opens Integrations, where you enable ACME, SPIFFE or a deployment adapter on a node.
    • Claim a discovered service: Authorize a measured workload, agent, or MCP server. Opens Service claims.
  3. Or copy the LOCAL CLI EXAMPLE with the copy button.
  4. Select Close.

The CLI example is built from your active policy. It uses the first workload profile that has a SPIFFE path prefix and appends my-service to that prefix:

Local CLI example (as shown in the console)
sectigo-edge cert issue --profile prod-service --spiffe-id spiffe://acme/prod/my-service

If your policy has no workload profile with a SPIFFE prefix, the example shows placeholders instead: sectigo-edge cert issue --profile <profile-id> --spiffe-id <spiffe-id>.

Check your CLI version before using this example

The operator CLI shipped with the current release (sectigo-edge) provides the status, integrations, discover, events, acme-eab-create, adcs-recover, mcp and version commands. It does not list a cert issue command. Until it does, request certificates through ACME, the SPIFFE Workload API, an SDK or a deployment integration. See Operator CLI.

In the demo workspace the dialog also has Run demo request, which adds a simulated certificate to the inventory.

Revoke a certificate​

Revocation is a one-party safety action: one authorized person can do it, and it cannot be undone. New issuance still needs both trust domains.

Revoke certificate immediately dialog with an RFC 5280 reason, the Promote healthy standby first option and an incident context box
The revoke dialog.
  1. Find the certificate and select Revoke in its row.
  2. In Revoke certificate immediately, choose the RFC 5280 reason.
  3. If the certificate set has a healthy standby, decide whether to keep Promote healthy standby first selected (it is selected by default).
  4. In Audited incident context, enter a ticket number, evidence or other context.
  5. Select Revoke now.

Revoke dialog fields​

FieldValues
RFC 5280 reasonKey compromise (default), Superseded, Cessation of operation, Affiliation changed, Privilege withdrawn, Certificate hold, Unspecified
Promote healthy standby firstOnly shown when the standby slot is healthy. Preserves service while immediately removing the compromised certificate.
Audited incident contextFree text stored with the revocation in the audit record.

What happens next​

The console confirms the outcome with one of these messages:

MessageMeaning
Standby promoted and compromised certificate revoked without downtime.Failover was selected and the standby was healthy.
Certificate revoked. Existing trust should be removed immediately.The certificate was revoked with no failover. Make sure the service stops using it.
Revocation is durably queued to the assigned Windows node. ADCS completion will update inventory and failover automatically.The certificate was issued through Microsoft ADCS; the Windows Mesh Node completes revocation locally.

The revoked serial is then published in the CA's revocation list and OCSP responses. See Revocation.

Permissions​

ActionRoles
View the inventoryEvery role
Request a certificate through a node or claimApplication Owner, PKI Operator, Tenant Admin (enforced when the workload requests issuance)
RevokePKI Operator, Tenant Admin. Requires MFA within the last ten minutes.

Troubleshooting​

SymptomCause and fix
Revoke is greyed outThe set has no active certificate, or it is already revoked.
Promote healthy standby first is not offeredThe set has no standby, or the standby is not healthy. Revoking will leave the service without a valid certificate until a replacement is deployed.
Revocation fails with a step-up or MFA messageYour MFA is older than ten minutes. Sign in again and retry.
A certificate shows — for algorithmThe console could not find the issuing transaction for its active certificate.