Import, Replace, or Remove a Certificate
Configuration → Settings → Certificates
Import a certificate NIM can use for HTTPS or connector authentication, replace it safely before expiry, and remove it only after dependent configuration is updated.
This guide covers importing .pfx and .p12 certificate files. For PGP public and private keys used in encrypted file exchange, use PGP encryption instead.
Before you make a changeDirect link to Before you make a change
.pfx or .p12 file containing the certificate, its private key, and the intermediate CA certificates for the NIM connection or HTTPS endpoint.Do not remove a certificate that is selected by an HTTPS endpoint, LDAP connection, or integration until the replacement is imported, selected, and tested. Removing an active certificate can interrupt sign-in or connector communication.
Include intermediate certificates before importDirect link to Include intermediate certificates before import
For a certificate issued by a certificate authority (CA), prepare the .pfx or .p12 outside NIM with the endpoint or client certificate, its matching private key, and every intermediate CA certificate in its issuing chain. Obtain the matching intermediate certificates from your issuing CA's download portal or your organization's PKI team. A self-signed certificate has no intermediate chain.
Intermediate certificates connect your certificate to a trusted root CA. If they are missing, importing the file can succeed while HTTPS access or certificate authentication still fails because the other system cannot build a trusted chain. A successful test on one computer is not enough: that computer may already have the missing intermediates cached or be able to download them.
The root CA must be trusted by the system validating the certificate. Including a root in a PFX does not establish that trust; HTTPS servers normally send the endpoint certificate and intermediates, rather than the root. For private CAs, coordinate root trust with your PKI team. See OpenSSL's certificate verification guidance.
Export from Windows with the certificate chainDirect link to Export from Windows with the certificate chain
On the Windows computer that holds the certificate and its exportable private key:
- Open
certlm.mscfor the local computer store, orcertmgr.mscif the certificate is in your current user's store. Find the certificate, commonly under Personal → Certificates. - Open the certificate and inspect Certification Path. Resolve missing intermediates with your PKI team before exporting; the export wizard cannot include certificates that it cannot find.
- Right-click the certificate and select All Tasks → Export. Choose Yes, export the private key, then Personal Information Exchange – PKCS #12 (.PFX).
- Select Include all certificates in the certification path if possible, protect the export with a password, and save the PFX. If private-key export is unavailable, ask the certificate owner or PKI team to provide a suitable file.
See Microsoft's certificate export instructions.
Build a PFX with OpenSSLDirect link to Build a PFX with OpenSSL
If you have PEM files, put all required intermediate certificates in intermediates.pem, with each complete BEGIN CERTIFICATE / END CERTIFICATE block on its own lines. Use certificate.pem for the endpoint or client certificate and private-key.pem for its matching private key:
openssl pkcs12 -export -out nim-certificate.pfx -in certificate.pem -inkey private-key.pem -certfile intermediates.pem
OpenSSL prompts for an export password and, if needed, the private-key password. The -certfile option adds the supplied certificates; it does not fetch missing intermediates. See the OpenSSL PKCS #12 documentation.
Check the exported file and test after importDirect link to Check the exported file and test after import
Inspect the certificates actually included in the PFX without exporting its private key:
openssl pkcs12 -in nim-certificate.pfx -nokeys -out included-certificates.pem
Confirm the output contains your certificate and each expected intermediate. Their presence alone does not prove the chain is valid. If you have the CA's root and intermediate PEM files, check the issuing chain separately:
openssl verify -CAfile root-ca.pem -untrusted intermediates.pem certificate.pem
Expect certificate.pem: OK. This checks against the root you supplied; it does not prove that other systems trust that root or that an HTTPS hostname matches. See the OpenSSL verification documentation.
Import the prepared PFX into NIM, select it for the intended endpoint or connection, and test from the systems that will use it. For HTTPS, include a client that does not already have the intermediates cached. If the chain is incomplete, rebuild or re-export the file with the missing intermediates, then follow the replacement sequence below.
Add a certificateDirect link to Add a certificate
1. Open the Certificates paneDirect link to 1. Open the Certificates pane
Go to Configuration → Settings → Certificates, then select Add.
2. Name and upload the certificateDirect link to 2. Name and upload the certificate
Enter a descriptive Certificate Name that includes its system, purpose, and renewal context, such as Entra-Production-ClientAuth-2026. Select the .pfx or .p12 file, enter its Password when required, then select Add.
3. Confirm the importDirect link to 3. Confirm the import
Confirm the certificate appears in the Certificates pane. Then select it in the HTTPS or connector configuration that needs it and run that connection’s test.
Connect the certificate to its purposeDirect link to Connect the certificate to its purpose
Importing a certificate does not automatically apply it to a connection. Update and test the item that needs it:
| Use case | Next action |
|---|---|
| HTTPS | Select the certificate while following Configure HTTPS, then verify browser access. |
| Microsoft Entra ID | Select the certificate in the Entra connection and run Test Connection. See Microsoft Entra ID connection setup. |
| Google Workspace | Select the imported certificate in the Google connection and run Test Connection. See Google Workspace connection setup. |
| Another connector | Select it in the connector’s connection configuration, then run the connection test or a controlled collection. |
Remove a certificateDirect link to Remove a certificate
Remove a certificate only when it is retired and no NIM feature depends on it.
1. Confirm it is safe to retireDirect link to 1. Confirm it is safe to retire
Identify every HTTPS endpoint, directory connection, integration, or workflow that could still use the certificate. If it is being renewed, import, select, and test the replacement first.
2. Remove the retired certificateDirect link to 2. Remove the retired certificate
Return to Configuration → Settings → Certificates and select Remove Certificate beside the retired certificate.
Confirm the removal.
3. Verify every affected dependencyDirect link to 3. Verify every affected dependency
Re-test the affected connection or endpoint to confirm the replacement remains active and all expected communication still works.
If import or connection testing failsDirect link to If import or connection testing fails
- Confirm the file is
.pfxor.p12and that its password is correct. - Confirm the certificate contains the private key required by the integration or HTTPS configuration.
- Check that the imported file includes every required intermediate CA certificate. Follow Include intermediate certificates before import to prepare and inspect the file outside NIM.
- Verify you selected the newly imported certificate in the dependent connection; simply adding it to the list is not enough.
- Review the certificate troubleshooting guidance for CA, TLS, proxy, and trust-chain errors.
- Use the certificate expiration notification tutorial to avoid last-minute replacement work.