Independent Certificate Renewal
Administrators can renew an expiring SSH certificate from Certificate Inventory without rotating the associated SSH key, when the key is still valid.
Independent certificate renewal supports certificate lifecycle continuity without forcing key rotation. This behavior applies when the current SSH key remains valid and only the certificate requires renewal.
Renewal Behavior
-
Certificate renewal is initiated from Certificate Inventory.
-
The existing SSH key is retained and is not regenerated or replaced.
-
A new certificate is issued and mapped to the existing key, provided policy and CA validations succeed.
-
Inventory metadata is updated to reflect the renewed certificate validity period and status.
When to Use Independent Renewal
Use independent renewal when the certificate is approaching expiry but the associated key remains compliant and does not require rotation.
Triggering Certificate Renewal
- Go to Menu > SSH > Inventory > Certificate Inventory.
- Select one or more certificates that are near expiry and linked to valid keys.
- From Actions, select Renew Certificate.
- Confirm the request to start renewal.
- Monitor request status in Automation > Service Request > All.
Expected Outcomes
-
The certificate is renewed without changing the key fingerprint.
-
No key deployment changes are applied when renewal succeeds.
-
Audit and workflow records capture renewal execution and result.
