{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/axis-camera-certificate-lifecycle-https-8021x/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
        "slug": "axis-camera-certificate-lifecycle-https-8021x",
        "url": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/axis-camera-certificate-lifecycle-https-8021x/"
        },
        "title": "Camera certificate lifecycle management: HTTPS and 802.1X are different jobs",
        "summary": "Axis documents distinct certificate roles for HTTPS server identity and 802.1X network authentication. Each needs ownership, expiry monitoring, renewal, and recovery testing.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:28:39+00:00",
        "modified_at": "2026-07-19T21:28:39+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 417,
        "potentially_affected": "Axis device estates using HTTPS, IEEE 802.1X, AXIS Device Manager, VMS certificate validation, RADIUS, a private or enterprise CA, or automated certificate renewal.",
        "dse_recommendation": "Separate HTTPS and 802.1X certificate inventories, assign trust and renewal ownership, and stage certificate changes before they can interrupt video or network access.",
        "primary_source": {
            "name": "Axis Communications — AXIS Device Manager Security Guide",
            "url": "https://help.axis.com/en-us/adm-security-guide",
            "published_on": null,
            "authority": "Axis Communications"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Two certificate purposes</h2>\n<p><strong>Source fact:</strong> The AXIS Device Manager Security Guide describes certificate lifecycle management as the continuing work of issuing, installing, inspecting, remediating, monitoring, and renewing certificates. AXIS Device Manager can manage HTTPS and IEEE 802.1X certificates, monitor expiration, and renew certificates before they expire.</p>\n<p>The roles are different. For HTTPS, a camera presents a server certificate and the connecting client validates it. Axis notes that in a common VMS architecture, the VMS server accesses cameras directly while operator clients receive live and recorded video through the VMS. In that scenario, the VMS trust store is central, though maintenance clients that connect directly also need the appropriate trust.</p>\n<p>For 802.1X, the camera uses a client certificate to authenticate itself to a RADIUS service before network access is allowed. Axis explains that an 802.1X environment typically requires managed switches, RADIUS infrastructure, a certificate authority, and staff to maintain and monitor it. The guide describes separate workflows for HTTPS server certificates and 802.1X client and authentication certificates.</p>\n\n<h2>Architecture determines the CA choice</h2>\n<p>Axis discusses using AXIS Device Manager as a private CA for private camera resources and using an enterprise-PKI intermediate CA for 802.1X. That recommendation belongs to the architecture described in the guide. It should not be generalized to public services, every enterprise PKI, or a design in which many clients connect directly to cameras.</p>\n<p>An expired, untrusted, incorrectly named, or unavailable certificate can break management, recording, or network admission. Renewal is therefore a production change. The source does not authorize replacing certificates without validating the VMS, RADIUS, switch, device, time, and recovery dependencies.</p>\n\n<h2>DSE lifecycle checklist</h2>\n<p><strong>DSE recommendation:</strong> This is DSE operational synthesis for Axis environments, not a universal PKI design.</p>\n<ol>\n<li>Inventory every certificate by device, purpose, issuer, subject, serial number, expiry, key location, and renewal owner.</li>\n<li>Separate HTTPS server identity from 802.1X client authentication and any MQTT or syslog certificates.</li>\n<li>Map which VMS, browser, management client, RADIUS server, and switch trusts which CA.</li>\n<li>Protect CA private keys and backups according to the organization&#8217;s approved key-management process.</li>\n<li>Set warnings early enough to investigate and stage renewal before expiration.</li>\n<li>Test representative certificate issuance, installation, trust, 802.1X admission, VMS recording, and direct maintenance access.</li>\n<li>Test expired, revoked, untrusted, or failed-renewal behavior and document an authorized recovery path.</li>\n<li>Review the inventory after device replacement, CA change, network redesign, or VMS migration.</li>\n</ol>\n\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://help.axis.com/en-us/adm-security-guide\" target=\"_blank\" rel=\"noopener noreferrer\">AXIS Device Manager Security Guide</a> — certificate lifecycle, HTTPS, 802.1X, CA, RADIUS, and trust guidance.</li>\n<li><a href=\"https://help.axis.com/en-US/axis-os-knowledge-base\" target=\"_blank\" rel=\"noopener noreferrer\">AXIS OS Knowledge Base</a> — current device certificate behavior and version-specific administration context.</li>\n</ul>",
        "content_text": "Two certificate purposes\nSource fact: The AXIS Device Manager Security Guide describes certificate lifecycle management as the continuing work of issuing, installing, inspecting, remediating, monitoring, and renewing certificates. AXIS Device Manager can manage HTTPS and IEEE 802.1X certificates, monitor expiration, and renew certificates before they expire.\nThe roles are different. For HTTPS, a camera presents a server certificate and the connecting client validates it. Axis notes that in a common VMS architecture, the VMS server accesses cameras directly while operator clients receive live and recorded video through the VMS. In that scenario, the VMS trust store is central, though maintenance clients that connect directly also need the appropriate trust.\nFor 802.1X, the camera uses a client certificate to authenticate itself to a RADIUS service before network access is allowed. Axis explains that an 802.1X environment typically requires managed switches, RADIUS infrastructure, a certificate authority, and staff to maintain and monitor it. The guide describes separate workflows for HTTPS server certificates and 802.1X client and authentication certificates.\n\nArchitecture determines the CA choice\nAxis discusses using AXIS Device Manager as a private CA for private camera resources and using an enterprise-PKI intermediate CA for 802.1X. That recommendation belongs to the architecture described in the guide. It should not be generalized to public services, every enterprise PKI, or a design in which many clients connect directly to cameras.\nAn expired, untrusted, incorrectly named, or unavailable certificate can break management, recording, or network admission. Renewal is therefore a production change. The source does not authorize replacing certificates without validating the VMS, RADIUS, switch, device, time, and recovery dependencies.\n\nDSE lifecycle checklist\nDSE recommendation: This is DSE operational synthesis for Axis environments, not a universal PKI design.\n\nInventory every certificate by device, purpose, issuer, subject, serial number, expiry, key location, and renewal owner.\nSeparate HTTPS server identity from 802.1X client authentication and any MQTT or syslog certificates.\nMap which VMS, browser, management client, RADIUS server, and switch trusts which CA.\nProtect CA private keys and backups according to the organization’s approved key-management process.\nSet warnings early enough to investigate and stage renewal before expiration.\nTest representative certificate issuance, installation, trust, 802.1X admission, VMS recording, and direct maintenance access.\nTest expired, revoked, untrusted, or failed-renewal behavior and document an authorized recovery path.\nReview the inventory after device replacement, CA change, network redesign, or VMS migration.\n\nOfficial references\n\nAXIS Device Manager Security Guide — certificate lifecycle, HTTPS, 802.1X, CA, RADIUS, and trust guidance.\nAXIS OS Knowledge Base — current device certificate behavior and version-specific administration context.",
        "content_markdown": "## Two certificate purposes\n\nSource fact: The AXIS Device Manager Security Guide describes certificate lifecycle management as the continuing work of issuing, installing, inspecting, remediating, monitoring, and renewing certificates. AXIS Device Manager can manage HTTPS and IEEE 802.1X certificates, monitor expiration, and renew certificates before they expire.\n\nThe roles are different. For HTTPS, a camera presents a server certificate and the connecting client validates it. Axis notes that in a common VMS architecture, the VMS server accesses cameras directly while operator clients receive live and recorded video through the VMS. In that scenario, the VMS trust store is central, though maintenance clients that connect directly also need the appropriate trust.\n\nFor 802.1X, the camera uses a client certificate to authenticate itself to a RADIUS service before network access is allowed. Axis explains that an 802.1X environment typically requires managed switches, RADIUS infrastructure, a certificate authority, and staff to maintain and monitor it. The guide describes separate workflows for HTTPS server certificates and 802.1X client and authentication certificates.\n\n## Architecture determines the CA choice\n\nAxis discusses using AXIS Device Manager as a private CA for private camera resources and using an enterprise-PKI intermediate CA for 802.1X. That recommendation belongs to the architecture described in the guide. It should not be generalized to public services, every enterprise PKI, or a design in which many clients connect directly to cameras.\n\nAn expired, untrusted, incorrectly named, or unavailable certificate can break management, recording, or network admission. Renewal is therefore a production change. The source does not authorize replacing certificates without validating the VMS, RADIUS, switch, device, time, and recovery dependencies.\n\n## DSE lifecycle checklist\n\nDSE recommendation: This is DSE operational synthesis for Axis environments, not a universal PKI design.\n\n- Inventory every certificate by device, purpose, issuer, subject, serial number, expiry, key location, and renewal owner.\n\n- Separate HTTPS server identity from 802.1X client authentication and any MQTT or syslog certificates.\n\n- Map which VMS, browser, management client, RADIUS server, and switch trusts which CA.\n\n- Protect CA private keys and backups according to the organization’s approved key-management process.\n\n- Set warnings early enough to investigate and stage renewal before expiration.\n\n- Test representative certificate issuance, installation, trust, 802.1X admission, VMS recording, and direct maintenance access.\n\n- Test expired, revoked, untrusted, or failed-renewal behavior and document an authorized recovery path.\n\n- Review the inventory after device replacement, CA change, network redesign, or VMS migration.\n\n## Official references\n\n- [AXIS Device Manager Security Guide](https://help.axis.com/en-us/adm-security-guide) — certificate lifecycle, HTTPS, 802.1X, CA, RADIUS, and trust guidance.\n\n- [AXIS OS Knowledge Base](https://help.axis.com/en-US/axis-os-knowledge-base) — current device certificate behavior and version-specific administration context."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
                "url": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Camera certificate lifecycle management: HTTPS and 802.1X are different jobs",
                        "item": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/#article",
                "identifier": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
                "url": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/",
                "headline": "Camera certificate lifecycle management: HTTPS and 802.1X are different jobs",
                "description": "Axis documents distinct certificate roles for HTTPS server identity and 802.1X network authentication. Each needs ownership, expiry monitoring…",
                "abstract": "Axis documents distinct certificate roles for HTTPS server identity and 802.1X network authentication. Each needs ownership, expiry monitoring, renewal, and recovery testing.",
                "articleBody": "Two certificate purposes\nSource fact: The AXIS Device Manager Security Guide describes certificate lifecycle management as the continuing work of issuing, installing, inspecting, remediating, monitoring, and renewing certificates. AXIS Device Manager can manage HTTPS and IEEE 802.1X certificates, monitor expiration, and renew certificates before they expire.\nThe roles are different. For HTTPS, a camera presents a server certificate and the connecting client validates it. Axis notes that in a common VMS architecture, the VMS server accesses cameras directly while operator clients receive live and recorded video through the VMS. In that scenario, the VMS trust store is central, though maintenance clients that connect directly also need the appropriate trust.\nFor 802.1X, the camera uses a client certificate to authenticate itself to a RADIUS service before network access is allowed. Axis explains that an 802.1X environment typically requires managed switches, RADIUS infrastructure, a certificate authority, and staff to maintain and monitor it. The guide describes separate workflows for HTTPS server certificates and 802.1X client and authentication certificates.\n\nArchitecture determines the CA choice\nAxis discusses using AXIS Device Manager as a private CA for private camera resources and using an enterprise-PKI intermediate CA for 802.1X. That recommendation belongs to the architecture described in the guide. It should not be generalized to public services, every enterprise PKI, or a design in which many clients connect directly to cameras.\nAn expired, untrusted, incorrectly named, or unavailable certificate can break management, recording, or network admission. Renewal is therefore a production change. The source does not authorize replacing certificates without validating the VMS, RADIUS, switch, device, time, and recovery dependencies.\n\nDSE lifecycle checklist\nDSE recommendation: This is DSE operational synthesis for Axis environments, not a universal PKI design.\n\nInventory every certificate by device, purpose, issuer, subject, serial number, expiry, key location, and renewal owner.\nSeparate HTTPS server identity from 802.1X client authentication and any MQTT or syslog certificates.\nMap which VMS, browser, management client, RADIUS server, and switch trusts which CA.\nProtect CA private keys and backups according to the organization’s approved key-management process.\nSet warnings early enough to investigate and stage renewal before expiration.\nTest representative certificate issuance, installation, trust, 802.1X admission, VMS recording, and direct maintenance access.\nTest expired, revoked, untrusted, or failed-renewal behavior and document an authorized recovery path.\nReview the inventory after device replacement, CA change, network redesign, or VMS migration.\n\nOfficial references\n\nAXIS Device Manager Security Guide — certificate lifecycle, HTTPS, 802.1X, CA, RADIUS, and trust guidance.\nAXIS OS Knowledge Base — current device certificate behavior and version-specific administration context.",
                "datePublished": "2026-07-19T21:28:39+00:00",
                "dateModified": "2026-07-19T21:28:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/axis-camera-certificate-lifecycle-https-8021x/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Camera certificate lifecycle management: HTTPS and 802.1X are different jobs"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Video Surveillance",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 417,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Axis Communications — AXIS Device Manager Security Guide",
                    "url": "https://help.axis.com/en-us/adm-security-guide"
                }
            }
        ]
    }
}