Administer > SA Core and component security > SA certificate management > Use SA in third-party certificate mode

Use SA in third-party certificate mode

When working in third-party Certificate Authority mode, SA generates certificate signing requests (CSRs) for all certificates used by the SA Core and Satellite components. You are responsible for submitting these CSRs to your external CA for signing and for providing the issued certificates back to SA. Once all certificates are available at your specified location, you can continue the installation of the Core and SA Agents.

Class certificates

In third-party certificate mode, SA components do not use Class certificates. Each SA component has its own, unique certificate for each machine where the component is installed.

Select third-party certificate mode

You can set SA to third-party certificate mode when installing or recertifying the SA Core. Make sure that all the SA Agents and the SA Core and Satellite components are upgraded to SA 10.60 or later.

Compromised certificates

SA does not support certificate revocation in third-party certificate mode either. To invalidate a compromised Core Component certificate, recertify the entire Core.