Self-Service PEM Certificate Management

Overview

Ternary supports self-serve client certificate (PEM) regeneration, allowing Ternary Admins to renew expiring certificates directly from the platform, without requiring customer support or engineering intervention. This feature improves security, operational control and uptime resilience by empowering customers to proactively manage their certificate lifecycles.

What this feature enables

  • With self-service PEM certificate management, Admins can:
  • Regenerate a certificate with one click, without leaving the Ternary platform user interface.
  • Monitor certificate health via status labels - Active, Expiring Soon, or Expired.
  • Securely download regenerated PEMs.
  • See automatic in-app expiry warnings ahead of time to avoid integration disruptions.
  • For MSPs: Partner Admins can view all active certificate(s) with issue and expiry dates by accessing each child tenant.

Why it matters

Challenge (Before)Improvement (Now)
Certificates expired every ~3 years with no visibilityCentral certificate overview with expiry tracking
Regeneration was not self-serveOne-click regeneration in Ternary
Past incidents caused downtimeInformative reminders at 90/60/30 days
Certificate distribution was manual and error-proneSecure download link with expiry
No traceability of regeneration actionsAudit log entries with user, timestamp, IP
Admin Certificate Management view

View all PEM certificates with:

ColumnDescription
Certificate NameName of the PEM certificate, typically tied to a specific Azure integration
Issue DateDate the certificate was originally generated
Expiration DateCertificate expiry date (Note: renewal must happen before this)
StatusActive/Expiring Soon/ Expired (with visual indication)
ActionsIncludes "regenerate" for eligible roles

Note: Certificates automatically enter an Expiring Soon state 30 days before expiration.

How self-service regeneration works

  1. Click Regenerate next to the relevant certificate.
  2. Confirmation modal appears: “Are you sure you want to renew the certificate? This will revoke the current certificate and create a new one. Any integrations using this certificate will need to be updated.”
  3. Click “Confirm”.
  4. The new certificate is available for download.

Expiration reminders (in-app only)

Ternary displays upcoming expiry status directly in the UI for certificate owners and Tenant Admins:

TimeframeNotification type
90 daysInformational reminder
60 daysReminder to begin renewal
30 daysCritical warning (status changes to Expiring Soon)
ExpiredCertificate marked as Expired, regeneration strongly recommended