To install certificates on AI Gateway, follow the steps below.
-
Access the Netskope AI Gateway Configuration Wizard using the CLI interface. For information on login details, see Log in information (change it).
-
Navigate to the Certificate Management menu.

-
Select Generate CSR and enter the followig CSR in the Certificate Management page.
- Common Name: Should match the AI Gateway host name. (need details)
- Organization Unit
- Email Address
- Country
- State
- City
After successful CSR generation, the Certificate Management page displays a confirmation message.
You should use this CSR to sign and generate a certificate for AI Gateway from RootCA or a well-known certificate provider. -
In the Certificate Management page, choose Install Certificate menu and install the generated certificate on the Netskope AI Gateway.

-
Copy the signed certificate in the Certificate Management page in the section Paste your signed certificate. On successful installation, the page displays a completion message.
The Netskope AI Gateway defaults to a self-signed certificate for HTTPS connections with the AI Agent. If you choose not to use a CA-signed certificate, you must configure the AI Agent to trust this self-signed certificate or bypass validation.

