The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure CAC authentication

Prev Next

Configure users to access Trellix ESM using Common Access Card (CAC) credentials in the browser rather than by logging on with user names and passwords. CAC settings contain client certificates that identify users, similar to the way server certificates identify websites. Before enabling CAC, identify which browsers support CAC and the Electronic Data Interchange Personal Identifier (EDI-PI) associated with CACs.

ActivClient is the only supported CAC middleware on Windows. To use CAC authentication on Trellix ESM from Windows using Internet Explorer, you must install ActivClient on the client computer. Once installed, the system uses ActivClient to manage CAC credentials instead of the native Smart Card manager in Windows. Work with your system administrator to ensure that ActivClient has been installed in your environment.

When relying on CAC validation for application authenticity, the system security depends on the security of the Certificate Authority (CA). If the CA is compromised, CAC-enabled logons are also compromised. To set up CAC logon, upload the CA root certificates, enable CAC logon, and enable a CAC user by setting the user name to the card holder's Fully Qualified Distinguished Name (FQDN). Card holders can then access Trellix ESM in CAC-enabled browsers without being prompted for a user name or password.

Trellix ESM supports Gem alto and the Oberthur ID One card readers.

Important

If your certificates or certificate authorities expire, all users might be locked out. A fail-safe switch is available on the terminal menu that turns off CAC authentication.

  1. Upload the CA root certificate.

    1. On your computer's Control Panel, click Internet OptionsContentCertificatesTrusted Root Certification Authorities.

    2. Select your current Root CA, then click Export.

    3. On the Certificate Export Wizard, click Next, then select Base-64 encoded X.509 and click Next.

    4. Enter the location and name for the file you are exporting, click Next, then click Finish.

    5. On the system navigation tree of the Trellix ESM console, access System Properties, click Login Security, then select the CAC tab.

    6. Click Upload, then browse to the file that you exported and upload it to Trellix ESM.

  2. From the Trellix ESM dashboard, click menu.png and select More Settings.

  3. On the system navigation tree, select Trellix ESM and click Settings.png.

  4. Click Login Security, then select the CAC tab.

  5. Select the CAC mode:

    • OFF — This is the default setting. CAC logon is disabled so users have to log on using the Trellix ESM logon prompt

    • OPTIONAL — CAC authentication is available, but if the user does not provide a certificate, the Trellix ESM logon prompt appears as if CAC mode were off.

    • REQUIRED — Only CAC-enabled logons can access the system. The logon prompt is never shown. Enter a security PIN in Required Mode Security PIN (IPv4) (PIN entered on the terminal menu to switch CAC mode to OPTIONAL if users are locked out of the system). The terminal menu recognizes PIN in IPv4 format (10.0.0.0).

  6. Upload the CA root certificates chain. You can view the certificate file or download it to a location you select.

  7. Certificate revocation lists (CRL) identify which revoked certificates. Manually upload a .zip file with CRL files. Upload the list of certificates that have been revoked or download them to a location you select.

  8. Set up an automatic retrieval schedule by typing the URL address and the frequency with which Trellix ESM polls for revocation file updates.

  9. Enable each CAC user.

    1. On System Properties, click Users and Groups, then enter the system password.

    2. In the Users table, highlight the name of the user, then click Edit.

    3. Replace the name in the Username field with the FQDN.

    4. (Optional) Enter the user name in the User Alias field.