Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Knowledge Center
  3. Support Information

Root CA expiry renewal - Action required before January 1, 2027

Avatar Kripa Thapa
August 03, 2026 10:48
Follow

The Root CA certificate expires on 1 January 2027. From that date, it will no longer be trusted, and all Guardsix SIEM or Guardsix Fleet (formerly Director) deployments will fail TLS validation across multiple components. Upgrade your deployment, or install the CA update helper plugin, before the deadline.

This is routine certificate lifecycle maintenance, not a response to a security incident.

Who's affected

Any Guardsix SIEM or Guardsix Fleet deployment that, on 1 January 2027, still trusts only the expired Guardsix SIEM Root CA. Affected components include:

  • Guardsix SIEM

  • Guardsix Fleet (formerly Director) components including,

    • Fabric

    • Fleet Management (formerly Director Console)

    • Federated investigations (formerly LPSM)

  • Support Connection

  • SIEM Data Node/SIEM Log Collection Connectors

  • Logpoint Agent (Standalone)

  • External or dependent integrations

If left unresolved, this causes TLS handshake failures, connectivity disruption, failed integrations, and interrupted agent communication.

If you are using the syslog collector for log collection with TLS enabled and have uploaded the default CA certificate, the certificate will expire on January 1, 2027. After this date, TLS handshakes will fail. To avoid this, upload the renewed CA certificate to the endpoint's TLS configuration.

What you need to do

Guardsix SIEM

Your SIEM version determines whether to upgrade or install the Guardsix SIEM Root CA update helper plugin.

Version

Required action before 1 January 2027

v7.10

Already bundles the renewed CA. No action needed.

v7.7.x–v7.9.x

Install the SIEMRootCAUpgrade plugin, or upgrade to v7.10+.

v7.6.x and earlier

Upgrade to v7.7.x – v7.9.x and install the helper plugin, or upgrade directly to v7.10+.

For details on product support, see Product Version Lifecycle Policy.

Guardsix Fleet (formerly Director)

Your Fleet version determines whether to upgrade or install the Guardsix Director Fabric Root CA update helper patch & Guardsix SIEM Root CA upgrade plugin.

Version

Required action before 1 January 2027

Fleet v2.11.x

  • Fabric v2.11.x

  • Federated investigations v2.11.x

Already bundles the renewed CA. No action needed.

Director Fabric v2.8.x–v2.10.x

Apply the Director_Fabric-RootCAUpgrade patch containing the renewed CA in Fabric and API servers or upgrade Fleet to version 2.11.+.

LPSM v2.8.x-v2.10.x

Apply the SIEMRootCAUpgrade plugin containing the renewed CA or upgrade to version Fleet v2.11.+.

v2.7.x and earlier

Upgrade to Guardsix Fleet v2.8.x - v2.10x, then follow instructions above, or upgrade directly to v2.11+.

After upgrading Guardsix Fleet, update every fabric-enabled SIEM instance to a version that contains the renewed CA. 

Agent Solution

Logpoint Agent (Standalone)

If you are using Logpoint Agent (Standalone) or a third-party syslog collector configured with TLS enabled, after January 1, 2027, the default CA certificate trusted by the endpoint will expire, and TLS handshakes will fail, even if the SIEM side has already been updated. To avoid this, upload the renewed CA certificate to the endpoint's TLS configuration.

For SIEM: CA update helper plugin

The SIEM CA update helper plugin installs the renewed Root CA on extended-support versions without a full product upgrade. It's supported on Guardsix SIEM v7.7.xv– v7.9.x. Install it before 1 January 2027 if you're staying on a supported extended-support release and can't upgrade to mainstream. See CA update helper plugin for release details.

For Director: Fabric CA update helper patch

The Director Fabric CA update helper patch installs the renewed Root CA on extended-support versions without a full product upgrade. It's supported on Director Fabric v2.8.x – v2.10.x. Install it on Fabric and API servers before 1 January 2027 if you're staying on a supported extended-support release and can't upgrade to mainstream. See CA update helper plugin for release details.

For LSPM: CA update helper plugin

The LPSM CA update helper plugin is the same as the SIEM plugin, and it installs the renewed Root CA on extended-support versions without a full product upgrade. It's supported on LPSM v2.8.x – v2.10.x. Install it before 1 January 2027 if you're staying on a supported extended-support release and can't upgrade to mainstream. See CA update helper plugin for release details.

FAQ

Do I have to upgrade, or can I use the helper plugin instead?
You can stay on SIEM v7.7.x – v7.9.x or Guardsix Fleet v2.8.x – v2.10.x and install the CA update helpers to remain connected past the deadline. Upgrading (SIEM v7.10+ / Fleet v2.11+) is recommended for the longest supported runway. The helper plugin is a valid alternative if upgrading isn't feasible.

What happens if I do nothing before 1 January 2027?
The expired Guardsix SIEM Root CA is no longer trusted. Expect TLS handshake failures, lost connectivity, and interrupted agent communication.

Is this a security incident?
No. The Guardsix SIEM Root CA has reached its planned expiry and is being replaced as routine maintenance.

Where can I get help planning my upgrade?
Contact Guardsix Support, or your partner/account contact, for help planning the upgrade or helper rollout.

Comments

Article is closed for comments.

Related articles

  • Root CA Update Plugin / Patch
Was this article helpful? 1 out of 1 found this helpful
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.