Skip to main content

Operations

These runbooks are for the people who keep Sectigo Edge running once it is installed: platform engineers, PKI operators, security on-call, and the auditors who check their work. Each page describes what you do in the console or on a Mesh Node, what Sectigo Edge enforces for you, and what to check afterwards.

Before you start​

Most operational actions change trust, so Sectigo Edge asks for more than a normal sign-in:

RequirementWhat it means for you
Fresh MFAPrivileged actions need a session that completed MFA within the last ten minutes. If yours is older, the action fails with step_up_required. Sign in again and retry.
The right roleEach action checks a specific permission, for example policy management, revocation, node management or break-glass. Missing permission returns 403. See Access and roles.
Exact confirmation textDestructive or authority-changing dialogs ask you to type a phrase such as PAUSE ISSUANCE or REFRESH CRL. The button stays disabled until the text matches exactly.
A second personRestoring authority (resuming issuance, activating a policy, approving a migration or a migration recovery) needs a different person. The approver must be a different enterprise identity from the requester. Using another email address for the same person does not count.
tip

Make sure at least two separate people hold each approval role before you need them. An incident is the worst time to find out that only one person can approve a resume.

Runbooks at a glance​

TaskWho usually does itPage
Replace a certificate without an outagePlatform engineerZero-downtime rotation
Move a fleet to a new algorithm or CA in wavesPKI lead + approverCryptographic migrations
Revoke a certificate and confirm relying parties see itSecurity on-callRevocation & CRL/OCSP
Change cryptographic policy safelyPolicy manager + reviewerPolicy changes & approvals
Stop new issuance during an incidentBreak-glass operatorIncident response & break-glass
Give an auditor verifiable proofAuditor / complianceAudit & evidence export
Wire Sectigo Edge into on-call alertingSREMonitoring & alerts
Replace a failed or lost Mesh NodePlatform engineerBackup & recovery of nodes
Decode an error codeAnyoneTroubleshooting

How Sectigo Edge behaves when something is wrong​

Three rules hold across every runbook in this section. Knowing them makes most symptoms easier to read.

  1. Existing certificates keep serving. A failed rotation, a paused tenant, an unreachable CA or an offline control plane never removes a certificate that is already deployed and valid.
  2. New authority fails closed. If Sectigo Edge cannot prove something is safe, such as missing evidence, a stale policy, too few healthy nodes or an unconfigured signer, it refuses the action and returns a specific error code. It does not fall back to a weaker path.
  3. Everything is audited. Every privileged action, approval and node report is added to a hash-chained audit log that you can export and verify independently.

In this section​