Create source sites

Prev Next

Create a source site from Server Settings.

For details about product features, usage, and best practices, click ? or Help.

  1. Select MenuConfigurationServer Settings, then select Source Sites.

  2. Click Add Source Site. The Source Site Builder wizard appears.

  3. On the Description page, type a unique repository name and select HTTP, UNC, or FTP, then click Next.

  4. On the Server page, provide the web address and port information of the site, then click Next.

    HTTP or FTP server type:

    • From the URL drop-down list, select DNS Name, IPv4, or IPv6 as the type of server address, then enter the address.

      Option

      Definition

      DNS Name

      Specifies the DNS name of the server.

      IPv4

      Specifies the IPv4 address of the server.

      IPv6

      Specifies the IPv6 address of the server.

    • The default TrellixHttp source site now defaults to HTTPS using Port 443 for secure communication. The source site comes with a pre-associated certificate valid for one year. For default Trellix source site, see Automatic Certificate management.

      Note

      For older agents that do not support secure port implementation, communication will automatically fall back to Port 80 (HTTP) as determined by the sitelist.xml.

    UNC server type:

    • Enter the network directory path where the repository resides. Use this format: \\<COMPUTER>\<FOLDER>.

  5. On the Credentials page, provide the Download Credentials used by managed systems to connect to this repository.

    Use credentials with read-only permissions to the HTTP server, FTP server, or UNC share that hosts the repository.

    HTTP or FTP server type:

    • Select Anonymous to use an unknown user account.

    • Select FTP or HTTP authentication (if the server requires authentication), then enter the user account information.

    UNC server type:

    • Enter domain and user account information.

  6. Click Test Credentials. After a few seconds, a confirmation message appears that the site is accessible to systems using the authentication information. If credentials are incorrect, check the:

    • User name and password.

    • URL or path on the previous panel of the wizard.

    • The HTTP, FTP or UNC site on the system.

  7. Click Next.

  8. Review the Summary page, then click Save to add the site to the list.

Automatic certificate management for the default Trellix source site

ePO - On-prem uses the Windows operating system trust store to validate HTTPS connections to Trellix source sites, including update.nai.com and download.nai.com.

When Trellix renews the certificate for a Trellix source site, ePO - On-prem detects the new certificate during the next successful Repository Pull. If the certificate validates against the Windows operating system trust store, ePO - On-prem automatically:

  • Updates the stored repository certificate.

  • Makes the updated certificate available on the Repository Certificate Management page.

No manual action is needed for routine certificate renewals on Trellix source sites.