Configure ePO - On-prem for certificate-based authentication

Prev Next

Before users access ePO - On-prem with certificate-based authentication, enable the authentication method and upload a signed CA certificate.

You must have a signed certificate in P7B, PKCS12, DER, or PEM format.

For details about product features, usage, and best practices, click ? or Help.

  1. Open the Edit User page.

    1. Select MenuUser ManagementUsers.

    2. Click New User, and specify a username.

  2. Select Enable certificate-based Authentication.

  3. Next to CA certificate for client certificate, click Browse, navigate to and select the certificate file, then click OK.

    When a file is applied, the prompt changes to Replace current CA certificate.

    Note

    Replace the certificate when it expires, or if your organization's security requirements change. For example, your organization might require SHA-256 certificates for authentication.

  4. (Optional) If you provided a PKCS12 certificate, enter a password.

  5. Configure any advanced or optional settings as needed.

    • If you have a certificate revocation list (CRL), click Browse, navigate to and select the CRL file, then click OK.

      Note

      The CRL file must be in PEM format.

    • (Optional) As an alternative or additional method of checking a certificate's authenticity, configure the Online Certificate Status Protocol (OCSP).

      1. Click Enable OCSP checking.

      2. Type the URL to the OCSP server.

      3. (Optional) Select Enable CRL Distribution Point checks when the Trellix ePO server receives no response from the OSCP.

        If the connection to the default OCSP URL fails, ePO - On-prem tries to connect to the certification authority CRL mentioned in the certificate under CRL Distribution Point Check instead.

      4. (Optional) Select Make the default OCSP URL the primary OCSP URL.

        If that connection fails, ePO - On-prem falls back to the other OCSP responder, if mentioned in the certificate under Authority Information Access.

    • To require certificate-based authentication for all remote users, click Remote users use the certificate to sign in.

    • To make the user name the same as the subject Distinguished Name (DN) specified in the certificate, click Default certificate user name is the subject DN.

    • Configure Active Directory Integration.

      Important

      For these settings to work, you must have Active Directory user logon enabled and the user group added to a permission set.

      • To automatically assign Active Directory users to a permission set, select Automatically assign permission for user logon with an Active Directory certificate.

      • To automatically create an ePO - On-prem user account for anyone who accesses ePO - On-prem with the valid AD certificate, select Automatically create users for Active Directory certificate owners.

  6. Click Save.

  7. Restart ePO - On-prem to activate certificate authentication.