Root CA expiry renewal - Action required before January 1, 2027
The Root CA certificate expires on 1 January 2027. From that date, it will no longer be trusted, and all Guardsix SIEM or Guardsix Fleet (formerly Director) deployments will fail TLS validation across multiple components. Upgrade your deployment, or install the CA update helper plugin, before the deadline.
This is routine certificate lifecycle maintenance, not a response to a security incident.
Who's affected
Any Guardsix SIEM or Guardsix Fleet deployment that, on 1 January 2027, still trusts only the expired Guardsix SIEM Root CA. Affected components include:
Guardsix SIEM
-
Guardsix Fleet (formerly Director) components including,
Fabric
Fleet Management (formerly Director Console)
Federated investigations (formerly LPSM)
Support Connection
SIEM Data Node/SIEM Log Collection Connectors
Logpoint Agent (Standalone)
External or dependent integrations
If left unresolved, this causes TLS handshake failures, connectivity disruption, failed integrations, and interrupted agent communication.
If you are using the syslog collector for log collection with TLS enabled and have uploaded the default CA certificate, the certificate will expire on January 1, 2027. After this date, TLS handshakes will fail. To avoid this, upload the renewed CA certificate to the endpoint's TLS configuration.
What you need to do
Guardsix SIEM
Your SIEM version determines whether to upgrade or install the Guardsix SIEM Root CA update helper plugin.
Version |
Required action before 1 January 2027 |
v7.10 |
Already bundles the renewed CA. No action needed. |
v7.7.x–v7.9.x |
Install the SIEMRootCAUpgrade plugin, or upgrade to v7.10+. |
v7.6.x and earlier |
Upgrade to v7.7.x – v7.9.x and install the helper plugin, or upgrade directly to v7.10+. |
For details on product support, see Product Version Lifecycle Policy.
Guardsix Fleet (formerly Director)
Your Fleet version determines whether to upgrade or install the Guardsix Director Fabric Root CA update helper patch & Guardsix SIEM Root CA upgrade plugin.
Version |
Required action before 1 January 2027 |
|
Fleet v2.11.x
|
Already bundles the renewed CA. No action needed. |
Director Fabric v2.8.x–v2.10.x |
Apply the Director_Fabric-RootCAUpgrade patch containing the renewed CA in Fabric and API servers or upgrade Fleet to version 2.11.+. |
LPSM v2.8.x-v2.10.x |
Apply the SIEMRootCAUpgrade plugin containing the renewed CA or upgrade to version Fleet v2.11.+. |
v2.7.x and earlier |
Upgrade to Guardsix Fleet v2.8.x - v2.10x, then follow instructions above, or upgrade directly to v2.11+. |
After upgrading Guardsix Fleet, update every fabric-enabled SIEM instance to a version that contains the renewed CA.
Agent Solution
Logpoint Agent (Standalone)
If you are using Logpoint Agent (Standalone) or a third-party syslog collector configured with TLS enabled, after January 1, 2027, the default CA certificate trusted by the endpoint will expire, and TLS handshakes will fail, even if the SIEM side has already been updated. To avoid this, upload the renewed CA certificate to the endpoint's TLS configuration.
For SIEM: CA update helper plugin
The SIEM CA update helper plugin installs the renewed Root CA on extended-support versions without a full product upgrade. It's supported on Guardsix SIEM v7.7.xv– v7.9.x. Install it before 1 January 2027 if you're staying on a supported extended-support release and can't upgrade to mainstream. See CA update helper plugin for release details.
For Director: Fabric CA update helper patch
The Director Fabric CA update helper patch installs the renewed Root CA on extended-support versions without a full product upgrade. It's supported on Director Fabric v2.8.x – v2.10.x. Install it on Fabric and API servers before 1 January 2027 if you're staying on a supported extended-support release and can't upgrade to mainstream. See CA update helper plugin for release details.
For LSPM: CA update helper plugin
The LPSM CA update helper plugin is the same as the SIEM plugin, and it installs the renewed Root CA on extended-support versions without a full product upgrade. It's supported on LPSM v2.8.x – v2.10.x. Install it before 1 January 2027 if you're staying on a supported extended-support release and can't upgrade to mainstream. See CA update helper plugin for release details.
FAQ
Do I have to upgrade, or can I use the helper plugin instead?
You can stay on SIEM v7.7.x – v7.9.x or Guardsix Fleet v2.8.x – v2.10.x and install the CA update helpers to remain connected past the deadline. Upgrading (SIEM v7.10+ / Fleet v2.11+) is recommended for the longest supported runway. The helper plugin is a valid alternative if upgrading isn't feasible.
What happens if I do nothing before 1 January 2027?
The expired Guardsix SIEM Root CA is no longer trusted. Expect TLS handshake failures, lost connectivity, and interrupted agent communication.
Is this a security incident?
No. The Guardsix SIEM Root CA has reached its planned expiry and is being replaced as routine maintenance.
Where can I get help planning my upgrade?
Contact Guardsix Support, or your partner/account contact, for help planning the upgrade or helper rollout.
Comments
Article is closed for comments.