Renew an Expired Certificate

If the SSL certificate of your B Series Appliance is about to expire, you must renew it following the instructions below. If you need to replace an existing certificate with one from another certificate authority, see Re-key or Re-issue an SSL Certificate.

 

Because the software on the B Series Appliance is built for your specific SSL certificate, please be proactive in contacting BeyondTrust Technical Support before your SSL certificate expires. This way, BeyondTrust Technical Support can build software to help migrate your connections.

The steps below will guide you through renewing a CA-signed certificate.

Purchase the Certificate Renewal

  1. Contact the certificate authority that signed your existing certificate to request a renewal.

    When a certificate is renewed, the original certificate data is used. You do not need to create a new certificate request, and no new intermediate or root certificates need to be installed.

  2. Many CAs keep the certificate request information on file. Others may require you to provide the original certificate request.

    If the CA requires a copy of the original certificate request, go to the /appliance > Security > Certificates page.

    Security > Certificates

    Security > Certificate Requests

    1. In the Security :: Certificate Requests section, click the subject of the certificate request which matches the original certificate's data.

     

     

    Security :: Certificates :: View Request

    1. Select and copy the Request Data, and then submit this information to your certificate authority.

 

Import the Certificate Files

  1. Once the certificate authority has responded to the request with the new certificate files, download all of the files to a secure location. This location should be accessible from the same computer used to access the /appliance interface.

Security > Certificates
Security :: Other Certificates

  1. Log into the /appliance interface of your BeyondTrust Appliance B Series. Go to Security > Certificates.
  2. In the Security :: Other Certificates section, click the Import button.

 

Security :: Import Certificate

  1. Browse to your new certificate file and click Upload.
  2. Your renewed certificate should now appear in the Security :: Certificates section. This new certificate can be identified by its Expiration, since this will be a later date than the original certificate.

 

SSL Certificate Auto-Selection

BeyondTrust uses Server Name Indication (SNI), an extension to the TLS networking protocol, to allow any SSL certificate stored on the B Series Appliance to be served to any client. Because most TLS clients send SNI information at the start of the handshaking process, this enables the B Series Appliance to determine which SSL certificate to send back to a client that requests a connection.

You may choose a default certificate to serve to clients who do not send SNI information with their request, or to clients who do send SNI information, but which does not match anything in the B Series Appliance database.

Security > Certificates

  1. Go to /appliance > Security > Certificates.

 

Security :: Certificates

  1. In the Default column, select the radio button for the certificate you wish to make default.

 

At this point, the B Series Appliance should be fully upgraded and operational with its new certificate. The old certificate may be removed and/or revoked as necessary.