What is happening On October 17, 2026 we are rotating the *.my.centrify.net certificate. The new certificate is issued by SSL.com, as part of a phased change in the Certificate Authority that issues certificates for Cloud Suite / Privileged Access Service (PAS) domains. Systems whose trusted certificate store does not contain the SSL.com root and intermediate certificates will not validate the new certificate.
This change is not limited to one domain. Going forward, all Cloud Suite / PAS certificates are planned to be issued by SSL.com as existing certificates come up for rotation. The SSL.com root and intermediate certificates will be required for those rotations as well, so installing them now prepares your systems for every future change rather than just this one.
This is separate from the centrify.com rotation completed on August 22, which used Sectigo. Installing the Sectigo certificates does not prepare you for October 17.
Who this affects This applies to any system that connects to a Delinea PAS or Cloud Suite tenant on my.centrify.net, including systems running the Cloud Suite client or the Server Suite agent joined to a cloud tenant, on Linux, Windows, or Solaris, and the Cloud Connector on Windows. Systems joined only to Active Directory with no cloud tenant are not affected, and customers of other Delinea products do not need to take any action.
Both intermediates are required. Add these alongside your existing Sectigo certificates rather than replacing them. The Sectigo certificates are still in use and must stay in place.
2. Make sure your systems are fully patched Systems missing operating system security patches are at higher risk of disruption during any service update, and current patch levels help your systems retrieve updated public root certificates automatically. Patching alone is not sufficient for this change, so complete step 1 as well.
How to check whether you are ready On Linux, list the SSL.com certificates in your trust bundle. All three should appear.
On Windows, open certlm.msc and confirm the SSL.com root appears under Trusted Root Certification Authorities and both SSL.com intermediates appear under Intermediate Certification Authorities.
Connecting to your tenant is not a valid readiness test. The current certificate is not SSL.com-issued, so a successful connection today does not confirm you are ready.
If the certificates are not installed by October 17 Affected systems will fail certificate validation and lose connectivity to the service. Nothing is permanently damaged. Installing the certificates and refreshing the trust store restores service, and on Linux it takes effect after restarting the agent.
This scheduled maintenance affects: BR (Privileged Access Service / Cloud Suite), US (Privileged Access Service / Cloud Suite), UK (Privileged Access Service / Cloud Suite), EU (Privileged Access Service / Cloud Suite), AU (Privileged Access Service / Cloud Suite), CA (Privileged Access Service / Cloud Suite), and SEA (Privileged Access Service / Cloud Suite).