Edit a certificate authority

After a CA is entered, its realm (ability to issue certificates for devices or users) can be changed.

Note: Editing a CA does not enable the certificate to be changed; certificates are immutable objects. If the intention is to renew a CA that is about to expire, you can add an additional CA to the same realm. After it is added, that CA can be used to issue new certificates for users or devices in that realm.

Errors are shown after you click Update.

Note: It is not possible to clear the option Trust as a device certificate authority when existing devices in the system are using certificates that are issued by this CA. Likewise, the Trust as a user certificate authority option cannot be cleared nor the realm name be changed if the CA is the only remaining issuer for its particular realm. Instead, those users or devices must be configured to a different realm or to use a different certificate before such a change is accepted by the system.