You can replace the default Trellix DLP Network - SaaS self-signed certificate with the certificate issued by a certificate authority (CA) or an intermediate CA so that other hosts on the network can validate the appliance's SSL certificate.
SSH must be enabled.
Tip
Downloading a CSR from the appliance ensures that the appliance's private key can't be inadvertently exposed.
220 host.domain.example PVA/SMTP Ready
Only ECDSA and RSA certificates and keys are allowed in the uploaded file. The certificate must be suitable for use as both a TLS server and a TLS client and the upload must include the whole certificate chain. Uploads can be in the following formats:
Follow your CA's instructions to get the request signed.
Follow the steps in the Setup Wizard help.
Use an SCP client, such as winscp, to copy the root CA and any intermediate CA certificates used to sign the appliance certificate to the
/home/admin/upload/cacertdirectory on the appliance.Use an SCP client, such as winscp, to copy the signed appliance certificate to the
/home/admin/upload/certdirectory on the appliance.Apply a Trellix Data Loss Prevention – SaaS policy.
See the policy assignment section in the Trellix ePolicy Orchestrator - SaaS Product Guide.