What it is
You paste or upload a PEM bundle (leaf certificate plus optional intermediates), TigerTrust validates the chain and extracts the Common Name and expiry date, and you select the deployment targets to push it to. The certificate lands in your inventory with full expiry alerting. Because the private key is optional, you can deploy the certificate to targets that handle the key separately — such as cloud load balancers that import certificates independently — or include the private key for targets that need the full bundle.When to use it
- Deploy a vendor-supplied TLS certificate to a customer-facing load balancer the day it arrives, without waiting for a PKI issuance process.
- Upload a certificate purchased through a traditional CA order form and push it to multiple targets in one wizard session.
- Bring an externally-issued certificate under expiry monitoring so you get an alert before it expires and the vendor needs to be contacted again.
- Deploy partner certificates to agent-managed hosts by including the private key in the upload.
Set it up
Paste the PEM bundle
Paste the certificate PEM (and optionally the intermediate chain, leaf first) into the text area. TigerTrust parses it immediately and shows the Common Name, SANs, issuer, and expiry date below the field. If the PEM is malformed the wizard shows an error before you proceed.
Add the private key (optional)
If you have the private key and the deployment target requires it, paste the private key PEM. Leave this field blank for targets that handle the key separately.
Select deployment targets
On the next step, choose the targets to deploy to. The target list shows all configured targets in your workspace. Select one or more.
What you’ll see
After submission, the certificate appears in Certificates with the issuer shown as the external CA. The expiry date is tracked and expiry alerts will fire as normal. The deployment job status is visible in Deployments > Jobs with per-target progress.Related
Certificate Deployment
Deployment targets, subscriptions, and job tracking.
CSR-Only Signing
Alternative for HSM environments where TigerTrust signs a CSR from your device.
Alert Rules
Create expiry alert rules targeting externally-issued certificates.