This guide gives you step-by-step instructions on how to install an SSL certificate on Ivanti Connect Secure, the SSL VPN appliance sold for years as Pulse Secure. You import the signed certificate in the admin console under System > Configuration > Certificates > Device Certificates, add the intermediate certificates so the chain is complete, and bind the result to your virtual ports.
A note on naming, because both are still in use. Ivanti acquired Pulse Secure on 1 December 2020 and renamed the range: Pulse Connect Secure became Ivanti Connect Secure (ICS), and the desktop app most people called Pulse Secure is now the Ivanti Secure Access Client. Only the branding changed for this task. The menu path, the button names, and the steps below are the same whether your appliance still shows Pulse branding on an older 9.1 or 22.x build or the newer Ivanti branding.
Generate a CSR code on Ivanti Connect Secure
If you have already generated the CSR code and received the SSL certificate from your CA, skip this section and jump straight to installing the certificate.
Creating a CSR (Certificate Signing Request) is part of the SSL certificate application process. The CSR is a block of encoded text that contains the domain you want to secure and the organization that owns it. When you generate the CSR on the appliance, it also creates your private key and keeps it on the device, which is why the signed certificate has to come back to the same appliance and into the same pending request.
You have two options:
- Use our CSR Generator to create the CSR automatically. It hands you both the CSR and the matching private key, which you then import together during installation.
- Follow our step-by-step tutorial on how to generate a CSR on Ivanti Connect Secure, which keeps the private key on the appliance.
Submit the CSR to your Certificate Authority during the order. Once the CA validates it and issues your certificate, continue with the installation below.
Install an SSL certificate on Ivanti Connect Secure
After the CA signs your certificate and sends the files to your inbox, download the ZIP archive and extract its contents on your computer. The exact steps below depend on where you generated the CSR, so follow the path that matches your situation.
If you generated the CSR on the appliance
- Log in to your Ivanti Connect Secure admin console.
- Navigate to System > Configuration > Certificates > Device Certificates.
- Under Certificate Signing Requests, click the Pending CSR link that corresponds to the certificate you want to install.
- At the bottom of the new window, in the Import signed certificate section, click Browse and select the certificate you downloaded (in PKCS#7 or DER format).
- Click Import.
Tip: after you import a certificate this way, save a copy of your system configuration. Go to Maintenance > Import/Export > Import/Export Configuration and click Save Config As to download the system.cfg file. This backup lets you restore the certificate and its private key if you ever need to.
If you generated the CSR somewhere else
If you created the CSR elsewhere (for example, with our CSR Generator), you will import the certificate together with its private key:
- From the status page of your certificate, click the View certificate button.
- In the new window, select the desired certificate format (PKCS#7, for example) and download the certificate.
- Navigate to System > Configuration > Certificates > Device Certificates and click Import Certificate & Key.
- Choose how your files are packaged, then fill in the fields:
- Certificate file: the signed certificate you downloaded.
- Private key file: the key you generated with the CSR.
- Password: the key or PKCS#12 password, if your file is protected by one.
- Click Import.
Note: if the certificate and key are combined in a single PKCS#12 file (.pfx or .p12), pick the If certificate file includes private key option on the import page. You then supply the one file plus its password, and leave the separate key field empty.
Import your intermediate certificate
To present a complete chain that browsers and clients trust, import the intermediate (CA) certificates:
- In the admin console, select System > Configuration > Certificates > Device Certificates and click the Intermediate Device CAs link. Take care to use this one and not Trusted Client CAs, which is the separate list used to validate certificates presented by clients, not to build your own chain.
- Click Import CA Certificate and browse to your intermediate certificate file.
- Click Import Certificate.
- If your CA supplied more than one intermediate, you can upload them in a single PEM file or repeat the import for each. Ivanti documents the chain being sent in descending order, starting with the root, so keep the certificates in that order inside a combined file rather than shuffling them.
Assign the certificate to your Virtual Ports
Importing a certificate does not put it into service. The final step is to bind it to the ports that serve VPN traffic, typically your internal and external ports:
- In your list of device certificates, double-click the old certificate you are replacing.
- Unbind it from any ports it is assigned to, then click Save Changes.
- Back in the list, double-click the new certificate.
- Select and add the relevant internal and external ports, then click Save Changes.
A port can only serve one device certificate at a time, so unbinding the old certificate first is what frees the port for the new one. Administrators connected through the port you are changing may see the session drop as the appliance switches certificates, so do this in a maintenance window if the VPN is in use.
Test your SSL installation
After you install the certificate, run a scan against your VPN’s public hostname to confirm the certificate is served correctly and the intermediate chain is complete. Our SSL Checker reports the certificate, the chain, and the protocols the appliance offers. If the report says the chain is incomplete, the intermediate was either imported into the wrong list or not imported at all: repeat the Intermediate Device CAs step above.
Frequently Asked Questions
Yes. Ivanti acquired Pulse Secure and rebranded the products. The Pulse Connect Secure VPN appliance is now Ivanti Connect Secure, and the Pulse Secure desktop client is now the Ivanti Secure Access Client. The admin console and the certificate installation workflow are unchanged, so these instructions apply to both the Pulse-branded and Ivanti-branded versions.
Log in to the admin console and go to System > Configuration > Certificates > Device Certificates. If you created the CSR on the appliance, open the matching Pending CSR and import the signed certificate. If you created the CSR elsewhere, click Import Certificate & Key and upload the certificate and private key (or a single PKCS#12 file).
The appliance accepts standard formats. When importing a signed certificate into a pending CSR, you can upload PKCS#7 or DER files. When importing a certificate with its key, you can supply separate certificate and key files or a combined PKCS#12 file (a .pfx or .p12), optionally protected by a password.
Yes. A missing intermediate is the most common cause of “untrusted certificate” warnings on Ivanti Connect Secure. After importing your device certificate, add the intermediate certificates through the Intermediate Device CAs link so the appliance presents a complete chain. A desktop browser can still connect in cases where a VPN client refuses, so confirm the fix with the client your users actually run and not only in a browser.
Importing a certificate does not switch it on by itself. You must bind it to your Virtual Ports. Double-click the old certificate and unbind it from its ports, then double-click the new certificate and assign your internal and external ports to it. Click Save Changes after each step.
Save 10% on SSL Certificates when ordering from SSL Dragon today!
Fast issuance, strong encryption, 99.99% browser trust, dedicated support, and 25-day money-back guarantee. Coupon code: SAVE10


