Skip to main content

Import, Replace, or Remove a Certificate

Configuration → Settings → Certificates

Import a certificate NIM can use for HTTPS or connector authentication, replace it safely before expiry, and remove it only after dependent configuration is updated.

This guide covers importing .pfx and .p12 certificate files. For PGP public and private keys used in encrypted file exchange, use PGP encryption instead.

Before you make a changeDirect link to Before you make a change

Certificate fileA .pfx or .p12 file containing the certificate, its private key, and the intermediate CA certificates for the NIM connection or HTTPS endpoint.
Private-key passwordThe password required to unlock the certificate file, if it was encrypted during export.
Purpose and ownerThe system or endpoint that uses the certificate and the person responsible for renewing it.
Replace before you remove

Do not remove a certificate that is selected by an HTTPS endpoint, LDAP connection, or integration until the replacement is imported, selected, and tested. Removing an active certificate can interrupt sign-in or connector communication.

Include intermediate certificates before importDirect link to Include intermediate certificates before import

For a certificate issued by a certificate authority (CA), prepare the .pfx or .p12 outside NIM with the endpoint or client certificate, its matching private key, and every intermediate CA certificate in its issuing chain. Obtain the matching intermediate certificates from your issuing CA's download portal or your organization's PKI team. A self-signed certificate has no intermediate chain.

Intermediate certificates connect your certificate to a trusted root CA. If they are missing, importing the file can succeed while HTTPS access or certificate authentication still fails because the other system cannot build a trusted chain. A successful test on one computer is not enough: that computer may already have the missing intermediates cached or be able to download them.

The root CA must be trusted by the system validating the certificate. Including a root in a PFX does not establish that trust; HTTPS servers normally send the endpoint certificate and intermediates, rather than the root. For private CAs, coordinate root trust with your PKI team. See OpenSSL's certificate verification guidance.

Export from Windows with the certificate chainDirect link to Export from Windows with the certificate chain

On the Windows computer that holds the certificate and its exportable private key:

  1. Open certlm.msc for the local computer store, or certmgr.msc if the certificate is in your current user's store. Find the certificate, commonly under Personal → Certificates.
  2. Open the certificate and inspect Certification Path. Resolve missing intermediates with your PKI team before exporting; the export wizard cannot include certificates that it cannot find.
  3. Right-click the certificate and select All Tasks → Export. Choose Yes, export the private key, then Personal Information Exchange – PKCS #12 (.PFX).
  4. Select Include all certificates in the certification path if possible, protect the export with a password, and save the PFX. If private-key export is unavailable, ask the certificate owner or PKI team to provide a suitable file.

See Microsoft's certificate export instructions.

Build a PFX with OpenSSLDirect link to Build a PFX with OpenSSL

If you have PEM files, put all required intermediate certificates in intermediates.pem, with each complete BEGIN CERTIFICATE / END CERTIFICATE block on its own lines. Use certificate.pem for the endpoint or client certificate and private-key.pem for its matching private key:

openssl pkcs12 -export -out nim-certificate.pfx -in certificate.pem -inkey private-key.pem -certfile intermediates.pem

OpenSSL prompts for an export password and, if needed, the private-key password. The -certfile option adds the supplied certificates; it does not fetch missing intermediates. See the OpenSSL PKCS #12 documentation.

Check the exported file and test after importDirect link to Check the exported file and test after import

Inspect the certificates actually included in the PFX without exporting its private key:

openssl pkcs12 -in nim-certificate.pfx -nokeys -out included-certificates.pem

Confirm the output contains your certificate and each expected intermediate. Their presence alone does not prove the chain is valid. If you have the CA's root and intermediate PEM files, check the issuing chain separately:

openssl verify -CAfile root-ca.pem -untrusted intermediates.pem certificate.pem

Expect certificate.pem: OK. This checks against the root you supplied; it does not prove that other systems trust that root or that an HTTPS hostname matches. See the OpenSSL verification documentation.

Import the prepared PFX into NIM, select it for the intended endpoint or connection, and test from the systems that will use it. For HTTPS, include a client that does not already have the intermediates cached. If the chain is incomplete, rebuild or re-export the file with the missing intermediates, then follow the replacement sequence below.

Add a certificateDirect link to Add a certificate

1. Open the Certificates paneDirect link to 1. Open the Certificates pane

Go to Configuration → Settings → Certificates, then select Add.

Step 1 of 3

Connect the certificate to its purposeDirect link to Connect the certificate to its purpose

Importing a certificate does not automatically apply it to a connection. Update and test the item that needs it:

Use caseNext action
HTTPSSelect the certificate while following Configure HTTPS, then verify browser access.
Microsoft Entra IDSelect the certificate in the Entra connection and run Test Connection. See Microsoft Entra ID connection setup.
Google WorkspaceSelect the imported certificate in the Google connection and run Test Connection. See Google Workspace connection setup.
Another connectorSelect it in the connector’s connection configuration, then run the connection test or a controlled collection.
Replacement sequenceImport the new certificate, select it in every dependent connection or endpoint, test each dependency, then remove the retired certificate.

Remove a certificateDirect link to Remove a certificate

Remove a certificate only when it is retired and no NIM feature depends on it.

1. Confirm it is safe to retireDirect link to 1. Confirm it is safe to retire

Identify every HTTPS endpoint, directory connection, integration, or workflow that could still use the certificate. If it is being renewed, import, select, and test the replacement first.

Step 1 of 3

If import or connection testing failsDirect link to If import or connection testing fails

  • Confirm the file is .pfx or .p12 and that its password is correct.
  • Confirm the certificate contains the private key required by the integration or HTTPS configuration.
  • Check that the imported file includes every required intermediate CA certificate. Follow Include intermediate certificates before import to prepare and inspect the file outside NIM.
  • Verify you selected the newly imported certificate in the dependent connection; simply adding it to the list is not enough.
  • Review the certificate troubleshooting guidance for CA, TLS, proxy, and trust-chain errors.
  • Use the certificate expiration notification tutorial to avoid last-minute replacement work.