The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Manage SSL certificates

Prev Next

Upload, download, and regenerate SSL certificates and the certificate revocation list (CRL). Schedule updates to the CRL.

If you want to schedule CRL updates, you need a valid URL from a CRL source.

You can apply a certificate from a file, generate a self-signed certificate, generate an authority-signed certificate, or regenerate the default certificate.

  1. From the dashboard, click GUID-0177D71C-5A80-43D5-9629-5D396CF2895F-low.png then System Information.

  2. Next to Manage Certificates, click Setup.

  3. Upload a certificate.

    1. Click Upload.

    2. Click OK in the informational pop-up window.

    3. In the Import File pop-up window, click Browse and select the CRT and Key files.

  4. Generate a self-signed certificate.

    1. Under Self-Signed Certificate, click Generate.

    2. Set the key size, location information, and organization information.

    3. Click Save.

  5. Generate an authority-signed certificate.

    1. Under Signed Certificate Request, click Generate.

    2. Set the key size, location information, and organization information.

    3. Click Save.

  6. Regenerate the default Trellix certificates.

    1. Click Regenerate.

    2. Click Yes in the pop-up window.

  7. Expand the Certificate Revocation List menu.

    GUID-DF01E120-C61E-4BEE-9850-25E37A4869F9-low.png
  8. Upload a certificate revocation list (CRL).

    1. Click Upload.

    2. In the Import File pop-up window, browse to the CRL file and select it.

    3. Click Confirm.

  9. Download the CRL.

    1. Click Download.

    2. Select a file location and click and save the file.

  10. Schedule regular updates of the CRL.

    1. Select Set up a retrieval schedule.

    2. Enter the URL of the CRL source.

    3. Set the update frequency.