Trinetri logo
Device Control

Certificate Management

Certificate Management in TRINETRI - from reviewing endpoint certificate inventory and creating install/delete certificate policies to deploying them on specific endpoints and verifying the results through task status and execution output.

  • 2 min
  • September 6, 2026

What You'll Learn

  • How to create a Certificate Management policy to install or delete a certificate
  • How to configure a Delete policy to target a specific certificate by common name
  • How to scope a certificate deployment to all endpoints or specific ones
  • Where to review an endpoint's certificate inventory and filter by expiration status
  • How to deploy a certificate policy and confirm it completed successfully

Frequently Asked Questions

What does a Certificate Management policy do? It installs or removes a certificate from a chosen certificate store (such as Trusted Root Certificate Authorities) at either the Computer or User configuration level. The policy only defines the change; it's applied to endpoints separately through a Policy Deployment.
What's the difference between the Install and Delete operations? Install lets you upload a certificate file (cer, crt, p12, or pfx) and, if needed, a password to protect it. Delete removes matching certificates from the selected store - either by targeting a specific certificate using its Common Name or Serial Number, so only the intended certificate is affected.
Can I see which certificates are installed on an endpoint? Yes. An endpoint's Certificates tab lists every certificate found on it, with All, Not Expired, and Expired filters, plus details like issuer, validity dates, signing algorithm, key algorithm, CA, and whether it's self-signed.
How do I roll out a certificate policy to endpoints? Create a Policy Deployment: choose a scope (all endpoints or specific ones), select the certificate policy, choose a deployment policy (for example, an instant deployment policy), optionally set up notifications, then publish.
How can I confirm a certificate change actually took effect? Open the deployment and check that its stage reaches Completed with full progress. You can also revisit the endpoint's Certificates tab afterward - an installed certificate will appear in the list, while a deleted one will no longer show up and the Expired/All counts will drop.
CTA background

Experience Trinetri Autonomous Platform in Action.