New in Orchestration Monitor: update agent certificates remotely

The Update agent certificate action is now available on the Orchestration Monitor, giving you a single, centralized way to refresh certificates across your environment.

This feature simplifies security maintenance and ensures your dynamic agents can quickly and reliably establish trust.
Key functionality
  • Quick access: The Update agent certificate action is available when you select a dynamic agent workstation running version 10.2.6 or later, and click Actions. This enables users to initiate the remote certificate download.
  • Direct download from primary domain manager: When triggered, this action performs the update of the remote dynamic agent certificates on all eligible workstations. The selected dynamic agent contacts the primary domain manager to directly download new certificates from the master domain manager <data_dir>/ssl/depot folder, replacing the existing certificates in the dynamic agent local truststore.
  • Simplified trust for external services: If you create the sub-folder <data_dir>/ssl/depot/additionalCAs on the master domain manager and populate it with public certificates for external services, the agent automatically downloads them and adds them to its local trust store. This ensures simple and immediate trust establishment for any services dependent on those auxiliary certificates.
Automatic recovery and rollback
To guarantee continuity of service, an automatic recovery mechanism has been implemented.

After the agent downloads and imports the new certificates, it attempts a primary connection to the reference primary domain manager. If the connection fails to establish within a period of 5 minutes, or if the downloaded certificates are expired or incorrectly formatted, the agent automatically reverts to the previous functional certificates. This process protects the agent from being permanently isolated due to a failed update.

Verification
You can verify the success of the agent certificate update process by checking the Certificate expiration column on the Orchestration Monitor. You can add the Certificate expiration column by modifying the table configuration.

For more information, see Orchestration Monitor overview