Action required: Install the SSL.com certificates on your Cloud Suite systems

Scheduled for Oct 17, 04:00 - 14:00 EDT

Scheduled

What is happening
On October 17, 2026 we are rotating the *.my.centrify.net certificate. The new certificate is issued by SSL.com, as part of a phased change in the Certificate Authority that issues certificates for Cloud Suite / Privileged Access Service (PAS) domains. Systems whose trusted certificate store does not contain the SSL.com root and intermediate certificates will not validate the new certificate.

This change is not limited to one domain. Going forward, all Cloud Suite / PAS certificates are planned to be issued by SSL.com as existing certificates come up for rotation. The SSL.com root and intermediate certificates will be required for those rotations as well, so installing them now prepares your systems for every future change rather than just this one.

This is separate from the centrify.com rotation completed on August 22, which used Sectigo. Installing the Sectigo certificates does not prepare you for October 17.

Who this affects
This applies to any system that connects to a Delinea PAS or Cloud Suite tenant on my.centrify.net, including systems running the Cloud Suite client or the Server Suite agent joined to a cloud tenant, on Linux, Windows, or Solaris, and the Cloud Connector on Windows. Systems joined only to Active Directory with no cloud tenant are not affected, and customers of other Delinea products do not need to take any action.

Action required before October 17, 2026

1. Install the SSL.com certificates

Root: SSL.com TLS RSA Root CA 2022

Intermediate: SSL.com TLS Transit RSA CA R2

Intermediate: SSL.com TLS Issuing RSA CA R1

All SSL.com certificates can be downloaded from https://www.ssl.com/repository

Both intermediates are required. Add these alongside your existing Sectigo certificates rather than replacing them. The Sectigo certificates are still in use and must stay in place.

Per-operating-system instructions are available in our Support KB: https://support.delinea.com/s/article/1772984332766

2. Make sure your systems are fully patched
Systems missing operating system security patches are at higher risk of disruption during any service update, and current patch levels help your systems retrieve updated public root certificates automatically. Patching alone is not sufficient for this change, so complete step 1 as well.

How to check whether you are ready
On Linux, list the SSL.com certificates in your trust bundle. All three should appear.

awk -v cmd='openssl x509 -noout -subject' '/BEGIN/{c=cmd}{print | c}/END/{close(c)}' /etc/ssl/certs/ca-certificates.crt | grep -i "ssl.com"

On Windows, open certlm.msc and confirm the SSL.com root appears under Trusted Root Certification Authorities and both SSL.com intermediates appear under Intermediate Certification Authorities.

Connecting to your tenant is not a valid readiness test. The current certificate is not SSL.com-issued, so a successful connection today does not confirm you are ready.

If the certificates are not installed by October 17
Affected systems will fail certificate validation and lose connectivity to the service. Nothing is permanently damaged. Installing the certificates and refreshing the trust store restores service, and on Linux it takes effect after restarting the agent.

Reach out to support@delinea.com if you encounter any challenges.
Posted Aug 25, 2026 - 16:06 EDT
This scheduled maintenance affects: BR (Privileged Access Service / Cloud Suite), US (Privileged Access Service / Cloud Suite), UK (Privileged Access Service / Cloud Suite), EU (Privileged Access Service / Cloud Suite), AU (Privileged Access Service / Cloud Suite), CA (Privileged Access Service / Cloud Suite), and SEA (Privileged Access Service / Cloud Suite).