Operations
These runbooks are for the people who keep Sectigo Edge running once it is installed: platform engineers, PKI operators, security on-call, and the auditors who check their work. Each page describes what you do in the console or on a Mesh Node, what Sectigo Edge enforces for you, and what to check afterwards.
Before you start
Most operational actions change trust, so Sectigo Edge asks for more than a normal sign-in:
| Requirement | What it means for you |
|---|---|
| Fresh MFA | Privileged actions need a session that completed MFA within the last ten minutes. If yours is older, the action fails with step_up_required. Sign in again and retry. |
| The right role | Each action checks a specific permission, for example policy management, revocation, node management or break-glass. Missing permission returns 403. See Access and roles. |
| Exact confirmation text | Destructive or authority-changing dialogs ask you to type a phrase such as PAUSE ISSUANCE or REFRESH CRL. The button stays disabled until the text matches exactly. |
| A second person | Restoring authority (resuming issuance, activating a policy, approving a migration or a migration recovery) needs a different person. The approver must be a different enterprise identity from the requester. Using another email address for the same person does not count. |
Make sure at least two separate people hold each approval role before you need them. An incident is the worst time to find out that only one person can approve a resume.
Runbooks at a glance
| Task | Who usually does it | Page |
|---|---|---|
| Replace a certificate without an outage | Platform engineer | Zero-downtime rotation |
| Move a fleet to a new algorithm or CA in waves | PKI lead + approver | Cryptographic migrations |
| Revoke a certificate and confirm relying parties see it | Security on-call | Revocation & CRL/OCSP |
| Change cryptographic policy safely | Policy manager + reviewer | Policy changes & approvals |
| Stop new issuance during an incident | Break-glass operator | Incident response & break-glass |
| Give an auditor verifiable proof | Auditor / compliance | Audit & evidence export |
| Wire Sectigo Edge into on-call alerting | SRE | Monitoring & alerts |
| Replace a failed or lost Mesh Node | Platform engineer | Backup & recovery of nodes |
| Decode an error code | Anyone | Troubleshooting |
How Sectigo Edge behaves when something is wrong
Three rules hold across every runbook in this section. Knowing them makes most symptoms easier to read.
- Existing certificates keep serving. A failed rotation, a paused tenant, an unreachable CA or an offline control plane never removes a certificate that is already deployed and valid.
- New authority fails closed. If Sectigo Edge cannot prove something is safe, such as missing evidence, a stale policy, too few healthy nodes or an unconfigured signer, it refuses the action and returns a specific error code. It does not fall back to a weaker path.
- Everything is audited. Every privileged action, approval and node report is added to a hash-chained audit log that you can export and verify independently.
In this section
Zero-downtime rotation
How rotation is staged so services never present an expired or mismatched certificate, and how to verify a rotation end to end.
Cryptographic migrations
Planning and executing algorithm and CA migrations across a fleet, with checkpoints and rollback.
Revocation & CRL/OCSP
Revoking certificates and confirming revocation status is visible through CRLs and OCSP to relying parties.
Policy changes & approvals
Proposing, reviewing and approving policy changes, and auditing who approved what.
Incident response & break-glass
What to do when a key is suspected compromised or a CA must be distrusted, including the break-glass procedure.
Audit & evidence export
Producing evidence packages for auditors and verifying their integrity.
Monitoring & alerts
Which signals to monitor, how to configure alerting, and how to route alerts to your on-call tooling.
Backup & recovery of nodes
Backing up Mesh Node state and recovering or replacing a failed node.
Troubleshooting
Diagnosing common problems with enrollment, issuance, rotation and integrations, with symptoms, causes and fixes.
FAQ
Answers to frequently asked questions about Sectigo Edge.