field note
Axis camera certificate rotation: what auto-renew misses
AXIS Device Manager renews HTTPS certificates automatically, but only when it is the CA and the nightly job runs. What that leaves uncovered on a real fleet.
2026-08-06
AXIS Device Manager can rotate certificates across many cameras at once, and it can renew them automatically, but only under conditions most fleets never verify. Automatic renewal applies when Device Manager is itself acting as the certificate authority, it happens ahead of the configured expiry warning, and it runs as a nightly job on the Device Manager server. Break any one of those and renewal quietly stops happening. Nothing on the camera announces it, and the first symptom on an 802.1X network is a camera that has left the building.
Pick the certificate authority before you touch a camera
The first decision determines everything downstream, and it is a fork rather than a preference.
Device Manager as the CA. It uses its own root certificate to issue server certificates for your devices, with no other CA involved. You generate the root, set a passphrase, and export the root certificate so other systems can be told to trust the cameras. Axis recommends against saving that passphrase in the tool.
Device Manager as an intermediate CA. If you already run a CA, this is the correct path. You import your existing CA certificate so Device Manager can sign device certificates underneath it, and the cameras chain up to the trust you already have.
Choosing the first when you already have a PKI creates a second, parallel trust root that nobody outside the security team knows exists. That becomes an audit finding later, and it is much harder to unwind once several hundred cameras are carrying certificates from it.
The common name choice you make once and live with
When Device Manager issues certificates it writes a common name into each one, and you choose whether that is the device IP address or the device host name. This looks like a formality during commissioning.
It is not. A certificate whose common name is an IP address is valid only for as long as the camera keeps that address. Re-address a site, move a camera to a different VLAN, or let a DHCP reservation lapse and the certificate no longer matches the thing presenting it. Every strict client rejects it. If your cameras have resolvable names, use them, and if they do not, understand that you have tied your certificate validity to your addressing plan staying still.
What automatic renewal actually covers
When Device Manager is the CA, the server certificates it generated renew on their own, ahead of the configured expiry warning, as part of the nightly job cycle. The expiry warning lead time is itself configurable, and an expiring CA certificate raises an alarm.
That is genuinely useful, and it is also narrower than people assume.
Three gaps are worth stating plainly:
It covers what Device Manager issued. Certificates that arrived some other way, from your own CA pushed by hand or from a commissioning engineer who did it their own way, are not in that renewal cycle.
It depends on a server staying alive. Renewal runs as a scheduled job. A management server that was rebuilt, retired, or quietly left off after a migration takes the renewal cycle with it, and the cameras carry on presenting certificates that are counting down.
The HTTPS server certificate is not the 802.1X client certificate. They serve different purposes and expiring hurts differently. An expired server certificate produces warnings. An expired 802.1X client certificate closes the switch port and takes the camera off the network entirely, along with your ability to fix it remotely. That failure and how it hits whole sites at once is covered in camera certificates: expiry, 802.1X, and rotation at fleet scale.
Three things that break quietly
Validation is ignored by default. Device Manager ships with certificate validation switched off, and it has to be, because devices on firmware 7.20 and later arrive pre-configured with a self-signed certificate that the tool cannot verify. Without that setting, it cannot add the device at all. The consequence is that the tool will happily report a healthy HTTPS connection while validating nothing. Turning validation back on after you have deployed real certificates is a separate, deliberate step, and skipping it means you never actually tested what you built.
Enabling HTTPS can stop recording. Axis is explicit that the video management system has to support HTTPS before you enable it on cameras. If it does not, the VMS cannot talk to the cameras, and there is no live view and no recording. This is a fleet-scale foot-gun: the change looks like a security improvement, applies cleanly to every camera, and takes the entire recording estate down at once.
Self-signed certificates pass a lazy check. A camera with the factory self-signed certificate has a certificate. An inventory that asks “does this device have a certificate” returns yes for every one of them and tells you nothing.
A note on the guide everyone is citing
The document that search engines currently surface for Axis certificate management is an Axis how-to from September 2018, tested against Device Manager 5.03 and camera firmware 6.50 and 7.30. The concepts in it hold up, and the specifics have moved on considerably since AXIS OS 11 and 12. The menu paths and requirements it lists are worth reading as the shape of the problem rather than as current instructions, and anything you plan to run against a modern fleet should be validated on a canary first. The same caution applies to any AI-generated summary of that document, which inherits its age without inheriting the date on the cover. Firmware track context for what your cameras are actually running is in AXIS OS upgrade paths explained.
Doing this across 500 cameras
The hard part of certificate rotation at scale has never been the rotation. It is knowing, on any given morning, which certificates exist, what issued them, when each one expires, and whether the thing you believe is renewing them is still running. A management server that stopped doing nightly jobs eight months ago looks identical to one that is working, right up until a site drops off an 802.1X network on a Saturday.
MentatNOC tracks every camera’s certificate and expiry date continuously, flags the ones drifting toward a wall while there is still time to act, and pushes renewals in staged waves that never break monitoring. It verifies what a device is actually presenting rather than what a management console believes it installed. The write-side detail is on the firmware, password, and certificate actions page, and you can see the rollout flow end to end in a live platform demo.
Choose the CA deliberately, use names rather than addresses where you can, turn validation back on when you are done, and confirm that whatever you believe is renewing certificates is still alive. The rotation itself is the easy part.