QS-WAN console · QNova Client

Certificate lifecycle management, from enrollment to revocation

Certificate lifecycle management here covers the whole life of a device certificate: issued against a single use enrollment token, renewed on the device when the tower signals a new one, repaired when it breaks, revoked when access ends, and re-signed when the authority above it rotates. One certificate per device, one place to end it.

What it is

What it is: one certificate per device, and a list of all of them

Certificate management in QS-WAN starts in the profile list. A profile holds several devices, each one with its own certificate, and expanding a profile puts three facts on every line.

Three facts

A common name

The name the certificate was issued to. It is on the device line, not in a file somebody has to open first.

An expiry date

The date this certificate stops working, on the same line. A panel of devices at risk gathers the ones running out, so nobody has to go looking.

A signature algorithm

The algorithm the certificate was signed with. It is chosen per user, when the user is created, rather than fixed once for the whole fleet.

One certificate per device, one place to end it. The expiry date stops living in a spreadsheet that gets updated on a quiet afternoon and starts living on the row, and the next section lets you run that life from one end to the other.

The mechanism

One certificate, from the token that issues it to the action that ends it

Press the panel and run a certificate through its whole life. Issue it against a token that then dies, renew it on the device, end it, bring it back, and rotate the authority above it.

Console Device What the console keeps Certificate authority Signs every device certificate Current CA algorithm: mldsa87 Eight options, RSA-2048 to ML-DSA-87 Needs every gateway connected Enrollment token One per device, sent by email single use, stored as a hash valid for 48 hours, burned on use Burned signs enrolls Laptop PQ pending PQ enrolled Revoked common name expiry date signature algorithm no certificate yet ML-DSA-65 EnrolledRenewedRevokedReinstatedAuthority rotated Nothing here is deleted The QNova Client, on the device Fetches it, installs it, and raises a native notification Revoking ends the certificate. It does not delete the line, and Reinstate brings it back.

Run one certificate through its whole life. Each button is an action that exists in the console, and the record on the right never loses a line.

The device is waiting. It carries no certificate yet, and the enrollment token has not been used.

The diagram reads left to right. On the left sits the console. At the top, the certificate authority signs every device certificate, and the rotation dialog reads Current CA algorithm mldsa87, with eight options available from RSA-2048 to ML-DSA-87. Underneath it is the enrollment token: one per device, sent by email, single use, stored as a hash, valid for 48 hours and burned on use. In the middle is the device line. Before a certificate is issued the badge reads PQ pending and the line is empty. Once the token is used the badge reads PQ enrolled and the line carries a common name, an expiry date and a signature algorithm, with a device certificate issued as ML-DSA-65. Revoking it turns the badge to Revoked and the line to a stopped state, and Reinstate brings it back. On the right is the record the console keeps: enrolled, renewed, revoked, reinstated and authority rotated, each one lit as it happens and none of them deleted. Along the bottom, the QNova Client on the device fetches a new certificate, installs it and raises a native notification. The buttons refuse an action that would do nothing: asking for a renewal before a certificate exists returns a sentence rather than changing anything.

A certificate is not a file you keep somewhere. It is a state on a row, with an authority above it and a record behind it. That is why ending one is an action you can reverse, and why the console declines an action that would do nothing rather than offering you a button that changes nothing.

Why this exists

Four things that go wrong without it

The spreadsheet updated on a quiet afternoon

The expiry date lives in somebody’s head and in a file that gets updated when its owner has time. The first warning that it went stale is a person who cannot connect.

The Monday after a weekend expiry

Something ran out on Saturday and the ticket on Monday reads that the VPN is down. The work starts before anybody knows which certificate it was.

The reinstall you talk somebody through

A certificate that breaks in the field turns into a phone call, and you are walking a person through a machine you cannot see.

The access somebody asks about six months later

When ending a contractor’s access deletes the history along with it, the only answer left is somebody trying to remember.

What you gain

What you stop doing by hand

If you run the network

The column tracks the dates, and the device repairs itself

You stop tracking expiry dates, because the column does it and the panel of devices at risk names the ones running out. You stop talking somebody through a reinstall, because the client repairs the profile.

And the Monday where something expired over the weekend, with the ticket reading that the VPN is down, turns into a panel you read on Thursday.

If you sign for it

Ending access is one action, and the history survives it

Revoking somebody is one action in one console, and it keeps the record rather than deleting the history.

When somebody asks about the contractor’s access six months after it ended, you read out a list instead of reconstructing one from memory and a mailbox.

How it works

Three steps, and the middle one is not yours

The device gets one token, and only one

Enrollment runs on a single use token: one per device, stored as a hash, valid for 48 hours, burned on use. If it expires before your colleague gets to it, resending the enrollment replaces the token hash and the validity in one step, so the old one dies the instant the new one starts. The full route is in device enrollment.

The certificate renews itself, and repairs itself

When the control tower signals a new certificate, the QNova Client fetches it, installs it, and raises a native notification. Nobody files a ticket. And when the connection log classifier sees a revoked or invalid certificate, it fetches a replacement instead of leaving the person stuck.

You end it, reinstate it, or rotate the authority above it

Revoke ends the certificates on a device, Revoke all does the whole profile, and Reinstate brings it back. It works in both directions, and the record survives. Reissue cert appears only once a certificate has actually expired, which is the console declining an action that would do nothing.

In detail

The detail your change board will ask about

Algorithms

Two levels, and we name the screen each one came from

The signature algorithm is chosen per user, when the user is created, rather than fixed for the fleet. The create user dialog shows it in the signature algorithm field, where a device certificate is issued with ML-DSA-65.

The authority above it sits at another level. The per gateway rotation dialog reads Current CA algorithm: mldsa87, with a selector for the next rotation.

Two uses, two levels. We name the screen each one came from rather than rounding them into a single number that would be wrong on one of the two.

The same crypto agility runs The Vault, which offers eight certificate authority options, from RSA-2048 to ML-DSA-87, and re-signs and redistributes the certificates itself.

Rotation

What a fleet wide rotation actually asks of you

Apply CA rotation is one action with three consequences:

  1. It regenerates the certificate authority and the server certificate
  2. It ships the new bundle to the fleet
  3. It restarts the VPN server on the gateway

It needs every gateway connected at the time it runs, so it is a scheduled operation with a date and a window around it. Anybody who sells it as one click has never run it.

Where this earns its place

Four mornings this changes

The expiry you read on Thursday

The Monday where something expired over the weekend, with the ticket reading that the VPN is down, turns into a panel you read on Thursday afternoon.

The contractor whose engagement ended

Revoke ends the certificates on the device, Revoke all does the profile, and the record stays behind. Six months later the answer is a list rather than a memory.

The certificate that broke in the field

The connection log classifier sees a revoked or invalid certificate and fetches a replacement, so the person keeps working instead of waiting for you to walk them through a reinstall.

The rotation you book instead of announcing

Fleet wide rotation needs every gateway connected and restarts the VPN server on the gateway, so it goes in the calendar with a window around it rather than into an afternoon.

Works better together

Where this sits in the rest of the console

These are not a related links box. Each one owns a piece of the same certificate, and the order is the order the certificate meets them.

01

Sends the single use token and gets the first certificate onto the device. It is where every certificate on this page starts.

02

Fetches the new certificate, installs it and raises the notification, and repairs a profile when the connection log classifier sees one that is broken.

03

Owns the authority above the certificate: eight certificate authority options, from RSA-2048 to ML-DSA-87, re-signed and redistributed across the fleet.

04

Owns the row the certificate sits on: who carries the device, which gateways it may reach, and what happens to the rest of the profile when one device is revoked.

What the tunnels these certificates open are made of is in post-quantum cryptography, the job they do is secure remote access, and every feature is listed in one place.

What this does not do

The limits, because they are what make the rest believable

It does not watch your public website certificates

The scope is the device and gateway certificates that decide which of your machines open a tunnel. If you need expiry watched on public web servers, this is not that tool.

Revoking somebody does not tell them

Revoke and Reinstate do not notify the person on the device. They find out by behaving differently, so telling them is still your job.

Fleet wide rotation is not something you run at eleven in the morning

It regenerates the certificate authority and the server certificate, ships the new bundle and restarts the VPN server on the gateway, and it needs every gateway connected. Book a window.

Reissue only appears once a certificate has expired

Until then the console does not offer it, because it would do nothing. That is fewer buttons than a console where everything is always clickable, and it is on purpose.

Questions people ask

The ones that come up first

What is certificate lifecycle management?

It is running the full life of a certificate: issuing it, renewing it before it expires, repairing it when it breaks, and revoking it when access ends. Here it covers device and gateway certificates across the QS-WAN console and the QNova Client.

What happens when a device certificate is close to expiring?

The control tower signals a new one, the client fetches and installs it, and the person gets a native notification. You see the date on the device line, and the closest ones gathered in the panel of devices at risk.

Can I run a certificate authority rotation in the middle of a working day?

No. It regenerates the certificate authority and the server certificate, ships the new bundle and restarts the VPN server on the gateway, and it needs every gateway connected at the time it runs. Book a window.

Does this cover my public website certificates?

No. The scope is device and gateway certificates inside your network. If you need expiry watched on public web servers, this is not that tool.

Bring us a device. We will issue a certificate and revoke it live.

An engineer, a console shaped like yours, and as long as you need. You watch a token get burned on use, a certificate land on the device, and that same certificate end and come back with the record intact. It is free and there is nothing to sign.

Scroll to Top