Automated TLS Certificate Renewal/Import for USG FLEX, FLEX H and ATP Series

Options
dpipro
dpipro image  ZCNE Certified
First Comment Friend Collector Seventh Anniversary ZCNE Switch Level 1 Certification - 2020

Hello,

We are using COMODO certificates on about 70 ZyWALL appliances.

With the recent CA/Browser Forum changes regarding the maximum validity period of publicly trusted TLS certificates, certificate lifecycle management is becoming increasingly important.

The transition has already started in March 2026, and the maximum certificate validity period will continue to decrease over the next few years, eventually reaching only 47 days in March 2029.

At the moment, on Zyxel firewall appliances such as the USG FLEX, USG FLEX H and ATP series, installing a renewed third-party TLS certificate still requires manual intervention. While certificate issuance and renewal can already be automated externally , there does not appear to be a supported method to automatically import the renewed certificate into the firewall and activate it.

With certificates eventually having a maximum lifetime of only 47 days, manually replacing certificates on multiple firewall appliances will become increasingly difficult to manage, particularly for MSPs and organizations managing larger Zyxel deployments.

Does Zyxel have any plans to introduce automated certificate lifecycle management for the USG FLEX, USG FLEX H and ATP families?

For example, this could be implemented through one or more of the following:

  • An API endpoint that allows certificates and private keys to be securely imported and activated;
  • CLI support for certificate import/replacement that could be used by automation tools;
  • Automated certificate retrieval and renewal from supported Certificate Authorities;

Even providing a supported API or CLI method for certificate import and activation would allow administrators and MSPs to integrate Zyxel firewalls into existing certificate automation workflows without requiring full native ACME support.

Considering the CA/Browser Forum roadmap, automated certificate management will soon move from being a convenience to becoming an operational requirement.

Is this functionality currently on Zyxel's roadmap for the USG FLEX, USG FLEX H and ATP series?

Thank you.

Best regards

All Replies

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @dpipro

    USG FLEX H in V1.39 supports Automated Certificate Management with Let's Encrypt. You may reference this FAQ to setup:

    For USG FLEX and ATP series (ZLD model), since these models are under maintenance mode, they will not support this feature.

    Zyxel Melen


  • PeterUK
    PeterUK image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    Options

    guess the USG FLEX and ATP series (ZLD model) are getting closer to EOL then…

  • dpipro
    dpipro image  ZCNE Certified
    First Comment Friend Collector Seventh Anniversary ZCNE Switch Level 1 Certification - 2020
    edited August 17
    Options

    Hi @Zyxel_Melen

    we are not using Let's Encrypt. We are using COMODO certificates on about 70 ZyWALL appliances (FLEX, ATP and FLEX H)

    Like us, there are many MSPs with dozens of appliances. It's inconceivable that ZyXEL would put MSPs in a situation like this!! HTTPS/SSL certificates are critical to protect the appliances from MITM attacks. ZyXEL should pay special attention to this; ignoring the problem and leaving MSPs to deal with a very high cost of certificate maintenance is a terrible response... I hope you reconsider...

    Best regards
  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @dpipro

    Thanks for your input. I have discussed with our product team about your inquiry. Our team want to discuss more details with you, therefore, I will open a private message for you and our team to discuss.

    Please help to check the private message I sent later.

    Zyxel Melen