Trusted CAs and the certificate ignore list¶
Open Trusted CAs to manage two independent lists:
| List | Effect |
|---|---|
| Trusted CAs | Register an internal or private root/intermediate certificate so a matching fingerprint is shown as trusted in your organization's chain views. |
| Ignore list | Exclude a CA certificate from expiry alerts and acknowledgement queues. It does not change trust. |
A CA may appear on either list, both, or neither. Adding or removing an ignore entry does not edit a trusted CA registration.
Administrators can add an ignore entry from the Trusted CAs page or an observed CA's certificate detail. Tenant administrators can manage tenant-wide entries, and authorized organization administrators can manage entries for their child organization. Tenant administrators can also choose whether to inherit CertIntel's default CA ignore policy.
Known public CA roots and intermediates in the current CCADB catalog are automatically excluded from expiry alerts. The Agent periodically receives the effective ignore policy for its reporting organization. It may skip uploading a matching certificate; for an internal endpoint configured in the dashboard, that produces a neutral skipped by policy check after the TLS handshake identifies the certificate.