diff --git a/ui-ngx/src/assets/help/en_US/device-profile/x509-chain-hint.md b/ui-ngx/src/assets/help/en_US/device-profile/x509-chain-hint.md
new file mode 100644
index 0000000000..f1aa10f921
--- /dev/null
+++ b/ui-ngx/src/assets/help/en_US/device-profile/x509-chain-hint.md
@@ -0,0 +1,18 @@
+##### X509 Certificate Chain info
+
+X.509 certificates strategy is used to provision devices by client certificates in two-way TLS communication.
+
+This strategy can:
+* check for pre-provisioned devices
+* update X.509 device credentials
+* create new devices
+
+The user uploads X.509 certificate to the device profile and sets a regular expression to fetch the device name from *Common Name (CN)*.
+
+Client certificates must be signed by X.509 certificate, pre-uploaded for this device profile to provision devices by the strategy.
+
+The client must establish a TLS connection using the entire chain of certificates (this chain must include device profile X.509 certificate on the last level).
+
+If a device already exists with outdated X.509 credentials, this strategy automatically updates it with the device certificate's credentials from the chain.
+
+Important: Uploaded certificates should be neither root nor intermediate certificates that are provided by a well-known *Certificate Authority (CA)*.
diff --git a/ui-ngx/src/assets/help/en_US/device-profile/x509-chain-regex-examples.md b/ui-ngx/src/assets/help/en_US/device-profile/x509-chain-regex-examples.md
new file mode 100644
index 0000000000..bb8a069473
--- /dev/null
+++ b/ui-ngx/src/assets/help/en_US/device-profile/x509-chain-regex-examples.md
@@ -0,0 +1,15 @@
+#### Examples of RegEx usage
+
+* **Pattern:** .* - matches any character (until line terminators)
+ **CN sample:** DeviceName\nAdditionalInfo
+ **Pattern matches:** DeviceName
+
+* **Pattern:** ^([^@]+) - matches any string that starts with one or more characters that are not the @ symbol (@ could be replaced by any other symbol)
+ **CN sample:** DeviceName@AdditionalInfo
+ **Pattern matches:** DeviceName
+
+* **Pattern:** [\w]*$ (equivalent to [a-zA-Z0-9_]\*$) - matches zero or more occurences of any word character (letter, digit or underscore) at the end of the string
+ **CN sample:** AdditionalInfo2110#DeviceName_01
+ **Pattern matches:** DeviceName_01
+
+**Note:** Client will get error response in case regex is failed to match.
diff --git a/ui-ngx/src/assets/locale/locale.constant-en_US.json b/ui-ngx/src/assets/locale/locale.constant-en_US.json
index ec9a151ede..de26259c00 100644
--- a/ui-ngx/src/assets/locale/locale.constant-en_US.json
+++ b/ui-ngx/src/assets/locale/locale.constant-en_US.json
@@ -1505,15 +1505,14 @@
"provision-secret-copied-message": "Provision secret has been copied to clipboard",
"provision-strategy-x509": {
"certificate-chain": "X509 Certificates Chain",
- "hint-certificate-chain": "X.509 certificates strategy is used to provision devices by client certificates in two-way TLS communication. This strategy can check for pre-provisioned devices, update X.509 device credentials, or create new devices. The user uploads X.509 certificate to the device profile and sets a regular expression to fetch the device name from Common Name (CN).
Client certificates must be signed by X.509 certificate, pre-uploaded for this device profile to provision devices by the strategy. The client must establish a TLS connection using the entire chain of certificates (this chain must include device profile X.509 certificate on the last level). If a device already exists with outdated X.509 credentials, this strategy automatically updates it with the device certificate's credentials from the chain.
Important: Uploaded certificates should be neither root nor intermediate certificates that are provided by a well-known Certificate Authority (CA).",
+ "certificate-chain-hint": "X.509 certificates strategy is used to provision devices by client certificates in two-way TLS communication.",
"allow-create-new-devices": "Create new devices",
- "hint-allow-create-new-devices": "Hint: if selected new devices will be created and client certificate will be used as device credentials.",
+ "allow-create-new-devices-hint": "Hint: if selected new devices will be created and client certificate will be used as device credentials.",
"certificate-value": "Certificate in PEM format",
"certificate-value-required": "Certificate in PEM format is required",
"cn-regex-variable": "CN Regular Expression variable",
"cn-regex-variable-required": "CN Regular Expression variable is required",
- "hint-cn-regex-variable": "Required to fetch device name from device's X509 certificate's common name.",
- "regex-examples": "Examples of RegEx usage:
Pattern:.* - matches any character (until line terminators) CN sample:DeviceName\\nAdditionalInfo Pattern matches:DeviceName
Pattern:^([^@]+) - matches any string that starts with one or more characters that are not the @ symbol (@ could be replaced by any other symbol) CN sample:DeviceName@AdditionalInfo Pattern matches:DeviceName
Pattern:[\\w]*$ (equivalent to [a-zA-Z0-9_]*$) - matches zero or more occurences of any word character (letter, digit or underscore) at the end of the string CN sample:AdditionalInfo2110#DeviceName_01 Pattern matches:DeviceName_01
Note: Client will get error response in case regex is failed to match."
+ "cn-regex-variable-hint": "Required to fetch device name from device's X509 certificate's common name."
},
"condition": "Condition",
"condition-type": "Condition type",