Zero-touch certificate management

Last published : Sep 25, 2026
In {{page.adm-product-name-short}}, you can configure zero-touch certificate management on the managed {{page.citrix-adc-generic}} instances running build 14.1-43.x and later. With zero-touch certificate management, you eliminate manual interventions and build an in-memory zero-touch certificate store to serve the application requests. Navigate to Infrastructure > SSL Dashboard > Zero-Touch Certificate Management to upload all the certificates and keys on {{page.adm-product-name-short}}, and enable it on the managed {{page.citrix-adc-generic}} instances. {{page.citrix-adc-generic}} periodically polls the certificate repository and delivers the necessary certificates as required.
With zero-touch certificate management, the following processes are automatically done by {{page.citrix-adc-generic}}:
  • Adding, binding, and linking the certificates
  • Providing the certificates and keys in a specific order or together
  • Installing and using the suitable certificates based on the requests
  • Deleting the expired certificates during the periodic polling cycle
For more information on how the zero-touch certificate works on {{page.citrix-adc-generic}} instances, see {{page.citrix-adc-generic}} zero touch certificate management.
As an administrator, you must ensure the following in {{page.adm-product-name-short}}:
  • {{page.citrix-adc-generic}} instances are running build 14.1-43.x or later and they are managed in {{page.adm-product-name-short}}.
  • Upload the certificates (in any format) and keys. Then, enable zero-touch on the managed {{page.citrix-adc-generic}} instances.
  • Ensure that a valid CA certificate is present on {{page.adm-product-name-short}}. If you have an updated Console CA certificate, upload the certificate before you enable zero-touch on the managed {{page.citrix-adc-generic}} instances. The following error message is displayed if no CA certificate present on {{page.adm-product-name-short}}:
    CA upload
Related information

Upload certificates

  1. Navigate to Infrastructure > SSL Dashboard > Zero-Touch Certificate Management.
  2. Click Get Started.
    Get started
  3. {{page.citrix-adc-generic}} instances running build 14.1-43.x or later are listed. You can either click Configure zero-touch to enable zero-touch or click Skip to proceed the next step.
  4. Click Upload to upload all the certificates (can be in any format, such as .pem, .cer, and .crt).
    Notes:
    • The certificate or key file must be less than 8192 bytes.
    • If you are uploading multiple certificates or key files, the maximum supported size is 50000 bytes.
    • If the certificates or key files are password-protected, ensure that you provide the password. If the password is not provided, the certificate or the key file is not uploaded.

Enable zero-touch certificate management

After you upload the certificates, you must enable zero-touch on the managed {{page.citrix-adc-generic}} instances.
  1. From the Zero-Touch Certificate Management page, click Configure zero-touch.
    Configure
  2. Click Add instances, select the instances, and then click Enable.
    Enable zero-touch
{{page.adm-product-name-short}} uses the default polling interval to poll all certificates from the {{page.citrix-adc-generic}} instances. You can use the Poll Now option to poll immediately.
In the SSL dashboard, you can also view zero-touch certificate usage that shows details about the active and inactive certificates.
SSL dashboard view

SSL filter mode support

A NetScaler® instance fetches the metadata of specific SSL certificates and private keys. Implementing this least privilege approach ensures that instances only access the assets they require, preventing a compromise on one instance from exposing your entire certificate infrastructure. This feature is especially useful for environments with multiple administrators managing a group of NetScaler instances for distinct purposes.
Some of the benefits are:
  • Security segmentation - Restricts metadata access at a per-NetScaler level to minimize the attack surface and adhere to organizational security policies.
  • Streamlined admin experience - Reduces complexity in multi-tenant or departmental deployments by showing administrators only the assets relevant to their group of NetScaler instances.
  • Optimized resource utilization - Prevents system memory bloating by fetching the metadata of only the required SSL certificates and private keys.
The filter mode configuration defines how NetScaler instances and SSL files interact through specific synchronization types. You can manage these settings through NetScaler Console to ensure that only the necessary metadata is fetched by each instance.
Component Sync Type Description
NetScaler Instance Custom Sync NetScaler instances in this mode fetch only the metadata for certificates and keys specifically mapped to the instance.
NetScaler Instance Global Sync NetScaler instances in this mode fetch the metadata for all uploaded certificates and private keys.
SSL Files Custom Files These files are specifically mapped to NetScaler instances in Custom Sync mode.
SSL Files Global Files Metadata for these files is fetched by all the NetScaler instances in Global Sync mode.

Configure filter mode settings

To configure filter mode, define synchronization types for your instances and files. This ensures a secure and optimized distribution of sensitive metadata.
You can now upload certificates and private keys directly using the upload button in the Certificate Files and NetScaler Instances sections.
SSL dashboard
To configure using the GUI:
  1. Upload New Files (Day Zero) - Navigate to Certificate Files and NetScaler Instances > Upload to add new assets. Select from one of the following sync types:
    • GLOBAL - Select to use global sync mode and complete the upload.
    • CUSTOM - Select to use custom sync mode, choose the specific instances for mapping, and then upload the files.
      SSL dashboard
  2. Move Existing Files (Day N) - To shift certificates and keys from global sync to custom sync mode, select the target NetScaler instances and click Add Existing Files.
  3. Select Domains - Once instances are selected, choose the relevant domains to trigger the shift. NetScaler Console automatically detects and shifts the corresponding certificates and private key files to custom sync mode.
  4. View Assets - Navigate to the landing page to view all the certificates and private key files mapped to each NetScaler instance in custom sync mode.
  5. Switch Sync Mode - To return instances to global sync mode, click Switch to Global Sync on the landing page.
    SSL dashboard