Not every certificate you manage was issued by TigerTrust. Vendors supply certificates for their software, external CAs issue certificates through a procurement process, and partners hand over PEM bundles that need to land on your infrastructure today. The partner certificate wizard lets you upload any of these, validate them, and push them to your targets — with full expiry tracking so you know when to go back to the vendor for a replacement.

What it is

You paste or upload a PEM bundle (leaf certificate plus optional intermediates), TigerTrust validates the chain and extracts the Common Name and expiry date, and you select the deployment targets to push it to. The certificate lands in your inventory with full expiry alerting. Because the private key is optional, you can deploy the certificate to targets that handle the key separately — such as cloud load balancers that import certificates independently — or include the private key for targets that need the full bundle.

When to use it

  • Deploy a vendor-supplied TLS certificate to a customer-facing load balancer the day it arrives, without waiting for a PKI issuance process.
  • Upload a certificate purchased through a traditional CA order form and push it to multiple targets in one wizard session.
  • Bring an externally-issued certificate under expiry monitoring so you get an alert before it expires and the vendor needs to be contacted again.
  • Deploy partner certificates to agent-managed hosts by including the private key in the upload.

Set it up

1

Open the import wizard

Go to Certificates and click Import > Upload partner certificate.
2

Paste the PEM bundle

Paste the certificate PEM (and optionally the intermediate chain, leaf first) into the text area. TigerTrust parses it immediately and shows the Common Name, SANs, issuer, and expiry date below the field. If the PEM is malformed the wizard shows an error before you proceed.
3

Add the private key (optional)

If you have the private key and the deployment target requires it, paste the private key PEM. Leave this field blank for targets that handle the key separately.
4

Select deployment targets

On the next step, choose the targets to deploy to. The target list shows all configured targets in your workspace. Select one or more.
5

Deploy

Click Deploy. TigerTrust adds the certificate to your inventory and queues deployment jobs to each selected target. You can monitor progress in Deployments > Jobs.

What you’ll see

After submission, the certificate appears in Certificates with the issuer shown as the external CA. The expiry date is tracked and expiry alerts will fire as normal. The deployment job status is visible in Deployments > Jobs with per-target progress.
Partner certificates are not automatically renewed by TigerTrust. You are responsible for obtaining a replacement from the vendor before expiry. Configure an expiry alert rule targeting externally-issued certificates to ensure you have advance notice. See Alert Rules for how to set this up.

Certificate Deployment

Deployment targets, subscriptions, and job tracking.

CSR-Only Signing

Alternative for HSM environments where TigerTrust signs a CSR from your device.

Alert Rules

Create expiry alert rules targeting externally-issued certificates.