The appliance automatically generates and maintains a self-signed server certificate with the reserved name system-self-signed. This is the global default certificate for the appliance. It can be used for Web UI sessions and on the Email Security — Server appliance, MTA email forwarding as well. You cannot delete this certificate, because it ensures secure access to the appliance Web UI and other applications in the factory default configuration. If an alternate HTTPS or MTA certificate is designated as the active certificate and is later deleted, the system self-signed-certificate is automatically restored as the active certificate.
The appliance hostname is the Common Name (CN) attribute for the system self-signed certificate. The certificate is automatically regenerated if the hostname changes. You can regenerate the certificate on demand to extend the expiration date, or to get updated default certificate attributes (such as the organization or email address).
The certificate is valid for one year. If you use the Web UI to regenerate the certificate, the expiration date is extended by 365 days (or the number of days defined for the "time remaining" default attribute). You can specify a non-default number of days if you use the CLI to regenerate the certificate.
Important
Self-signed certificates are not included in the trusted root of many browsers, because they are not issued by a trusted certificate authority. Security warnings could be displayed to users when they navigate to the appliance Web UI. To prevent the warning from appearing again, the Web UI user can add the certificate to the browser's trusted root.
Operator or Admin access