To generate a new CA in the Admin Web UI, use the workflow for your Access Server version:
- For Access Server version 3.x, navigate to Certificate Management > VPN Server Certificate Authority, then select New CA Certificate.
- For Access Server version 2.x, navigate to Configuration > CA Management, then select Create New CA.
Adding the new CA restarts Access Server. After the restart, the new CA is labeled as current, and most VPN clients continue using previous certificates until users import or download new profiles. Administrators should verify migration status before deleting the previous CA because deleting a CA invalidates all connection profiles signed by it.