---
title: "Manage certificate authority"
canonical: "https://docs.aryaka.com/space/KNOW/1608984/Manage%20certificate%20authority"
format: markdown
---
The Certificate Authority page allows you to revoke, change, or regenerate your certificate authority. A certificate authority is used to sign dynamically generated certificates involved in SSL inspection.  If it is not already open, complete the following procedure to display the Certificate Authority page: To open the Certificate Authority page Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page displays a series of tiles. Click  Certificate   Authority  in the Vault tile. The Certificate Authority page appears. It includes the following: Two certificate authority tiles Certificate authority details Certificate authority tiles There are two certificate authority (CA) options—Aryaka CA, which is the Aryaka certificate, or Enterprise CA, which is your organization's certificate. Aryaka CA Aryaka CA is used as the default certificate authority. When Aryaka is the current certificate authority, the Aryaka CA tile displays the following two options: Regenerate Aryaka CA—Renews the Aryaka CA. Download Aryaka Trust Chain—Downloads the Aryaka trust chain to your local computer. When Enterprise is the current certificate authority, the Aryaka tile displays  Switch to Aryaka CA . Select this option to make Aryaka the current certificate authority.  Enterprise CA You can choose to use your company as the certificate authority instead of Aryaka.  The Enterprise CA tile displays the following three options: Generate CSR (certificate signing request) Upload Signed CA Upload Trust Chain Complete these tasks to use your company as the current certificate authority. To switch from Aryaka CA to Enterprise CA Click  Generate CSR . The Certificate Authority dialog appears and displays fields populated with default values for your organization. Complete the following procedure: Modify the following fields for your enterprise as needed: Common Name Organization Organization Unit Locality State/Province Country Click  Generate CSR . The certificate signing request is downloaded to your local computer as a .csr file. Sign the certificate signing request.  Click  Upload Signed CA , navigate to your signed CSR, then click  Upload . (Conditional) If your CSR does not contain a trust chain, click  Upload Trust Chain , navigate to your trust chain, and click  Upload .  Certificate authority details The Certificate Authority Details section displays the following details about the current certificate authority: Certificate Name State Serial Number Issuer Subject Valid From Valid Until Related topics Manage trust store Manage site dynamic certificates Manage static certificates Add static certificates Convert certificate file formats