Automated TLS Certificate Renewal/Import for USG FLEX, FLEX H and ATP Series
Hello,
We are using COMODO certificates on about 70 ZyWALL appliances.
With the recent CA/Browser Forum changes regarding the maximum validity period of publicly trusted TLS certificates, certificate lifecycle management is becoming increasingly important.
The transition has already started in March 2026, and the maximum certificate validity period will continue to decrease over the next few years, eventually reaching only 47 days in March 2029.
At the moment, on Zyxel firewall appliances such as the USG FLEX, USG FLEX H and ATP series, installing a renewed third-party TLS certificate still requires manual intervention. While certificate issuance and renewal can already be automated externally , there does not appear to be a supported method to automatically import the renewed certificate into the firewall and activate it.
With certificates eventually having a maximum lifetime of only 47 days, manually replacing certificates on multiple firewall appliances will become increasingly difficult to manage, particularly for MSPs and organizations managing larger Zyxel deployments.
Does Zyxel have any plans to introduce automated certificate lifecycle management for the USG FLEX, USG FLEX H and ATP families?
For example, this could be implemented through one or more of the following:
- An API endpoint that allows certificates and private keys to be securely imported and activated;
- CLI support for certificate import/replacement that could be used by automation tools;
- Automated certificate retrieval and renewal from supported Certificate Authorities;
Even providing a supported API or CLI method for certificate import and activation would allow administrators and MSPs to integrate Zyxel firewalls into existing certificate automation workflows without requiring full native ACME support.
Considering the CA/Browser Forum roadmap, automated certificate management will soon move from being a convenience to becoming an operational requirement.
Is this functionality currently on Zyxel's roadmap for the USG FLEX, USG FLEX H and ATP series?
Thank you.
All Replies
-
Hi @dpipro
USG FLEX H in V1.39 supports Automated Certificate Management with Let's Encrypt. You may reference this FAQ to setup:
For USG FLEX and ATP series (ZLD model), since these models are under maintenance mode, they will not support this feature.
Zyxel Melen0 -
guess the USG FLEX and ATP series (ZLD model) are getting closer to EOL then…
0 -
Hi @Zyxel_Melen
we are not using Let's Encrypt. We are using COMODO certificates on about 70 ZyWALL appliances (FLEX, ATP and FLEX H)
Like us, there are many MSPs with dozens of appliances. It's inconceivable that ZyXEL would put MSPs in a situation like this!! HTTPS/SSL certificates are critical to protect the appliances from MITM attacks. ZyXEL should pay special attention to this; ignoring the problem and leaving MSPs to deal with a very high cost of certificate maintenance is a terrible response... I hope you reconsider...
Best regards0 -
Hi @dpipro
Thanks for your input. I have discussed with our product team about your inquiry. Our team want to discuss more details with you, therefore, I will open a private message for you and our team to discuss.
Please help to check the private message I sent later.
Zyxel Melen0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 237 Nebula Ideas
- 6.8K Security
- 740 USG FLEX H Series
- 376 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 319 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 91 About Community
- 119 Security Highlight
ZCNE Certified
Zyxel Employee
Guru Member