Certificate Management
In addition to the Built-In CA for automatically issued certificates, Relution offers two further views for certificate management: Certificates for manually uploaded certificate files, and Issued Certificates for an overview of certificates installed on devices.
Certificates (manually uploaded)
Under Settings → Certificates, existing certificate files can be uploaded and managed (e.g. crt, cer, pfx/pkcs12, pem).
Required fields when uploading
- Name: Name of the certificate.
- Certificate file: The certificate file to upload.
Optional
- Password: Password for the certificate file, if encrypted.
An uploaded certificate can then be selected in many policy configurations as a generic certificate — similar to a Built-In CA certificate template, but without automatic per-device issuance. Typical use cases include VPN, Wi-Fi (EAP-TLS), and Exchange/email configurations, as well as Windows and Android Enterprise certificate configurations.
Issued Certificates (Device Certificates)
Under Settings → Issued Certificates, an overview is available of all certificates automatically issued for a device by a certificate policy (Built-In CA/SCEP) — including the certificate, device, certificate template used, certificate authority, and issuance, expiry, and (if applicable) revocation dates.
Manual issuance is not possible from this view — certificates are only created as the result of an enrollment or policy process. Two actions are available:
- Delete: Removes the entry from Relution. Not possible if the certificate must be revoked instead.
- Revoke: Revokes the certificate via the certificate revocation list (CRL) of the associated certificate authority. Select a revocation reason (e.g. key compromise, CA compromise, affiliation changed, superseded, cessation of operation, privilege withdrawn).