Netskope is rotating the TLS certificate chain used by the NPA Management Plane, migrating from GlobalSign R3 to GlobalSign R46. The change is designed to maintain the security and reliability of the NPA Management Plane. No action is required for data-plane traffic or existing private application connections; however, customers running older NPA Publishers or Local Brokers must upgrade before September 19, 2026, to maintain management-plane functionality.
1. What Is Changing? (5 min)
Netskope is replacing the GlobalSign R3 certificate chain with R46 for the NPA Management Plane.
This change affects the TLS trust requirements for NPA components that communicate with the Management Plane.
No changes are required to private application access.
Potential Impact Without the Required Upgrade
Older NPA Publisher and Local Broker versions may experience:
Enrollment/re-enrollment failures
Configuration synchronization failures, including GSLB, endpoints, and feature flags
Inability to enable or toggle features, such as Auto-Reconnect
Why Is This Happening?
Older NPA component versions are hard-pinned to the deprecated GlobalSign R3 certificate and do not support the new R46 certificate chain.
3. Required Action (10 min)
Upgrade all applicable NPA components before September 19, 2026:
Component
Required Version
NPA Publisher
R140.1 or later
Local Broker
R141 or later
Customer Action
Complete the required upgrades before September 19, 2026 to ensure uninterrupted NPA Management Plane functionality and avoid enrollment, synchronization, or feature-management issues.
Key takeaway: The certificate rotation does not impact NPA data-plane traffic or existing private application connections. The upgrade is required to ensure continued Management Plane operations.