The ePO - On-prem software deployment infrastructure supports deploying products and components, as well as updating both.
Each product that ePO - On-prem can deploy provides a product deployment package .zip file. The .zip file contains product installation files, which are compressed in a secure format. ePO - On-prem can deploy these packages to any of your managed systems.
The software uses these .zip files for both detection definition (DAT) and engine update packages.
You can configure product policy settings before or after deployment. We recommend configuring policy settings before deploying the product to network systems. Configuring policy settings saves time and ensures that your systems are protected as soon as possible.
These package types can be checked in to the Main Repository with pull tasks, or manually.
Supported package types
Package type | Description | Origination |
|---|---|---|
SuperDAT files (SDAT.exe) files File type: SDAT.exe | The SuperDAT files contain both DAT and engine files in a single update package. If bandwidth is a concern, we recommend updating DAT and engine files separately. | Trellix website. Download and check SuperDAT files into the Main Repository manually. |
Supplemental detection definition (Extra.DAT) files File type: Extra.DAT | The Extra.DAT files address one or more specific threats that have appeared since the last DAT file was posted. If the threat has a high severity, distribute the Extra.DAT files immediately, rather than wait until the signature is added to the next DAT file. Extra.DAT files are from the Trellix website. You can distribute them through ePO - On-prem. Pull tasks do not retrieve Extra.DAT files. | Trellix website. Download and check supplemental DAT files in to the Main Repository manually. |
Product deployment and update packages File type: zip | A product deployment package contains installation software. | Product CD or downloaded product .zip file. Check product deployment packages into the Main Repository manually. For specific locations, see the documentation for that product. |
Trellix Agent language packages File type: zip | A Trellix Agent language package contains files necessary to display Trellix Agent information in a local language. | Main Repository — Checked in at installation. For future versions of the Trellix Agent, you must check Trellix Agent language packages into the Main Repository manually. |
Package signing and security
All packages created and distributed by Trellix are signed with a key pair using the DSA (Digital Signature Algorithm) signature verification system. The packages are encrypted using 168-bit 3DES encryption. A key is used to encrypt or decrypt sensitive data.
You are notified when you check in packages that Trellix has not signed. If you are confident of the content and validity of the package, continue with the check-in process. These packages are secured in the same manner previously described, but ePO - On-prem signs them when they are checked in.
The Trellix Agent only trusts package files signed by ePO - On-prem or Trellix. This feature protects your network from receiving packages from unsigned or untrusted sources.
Package ordering and dependencies
If one product update depends on another update, check in the update packages to the Main Repository in the required order. For example, if Patch 2 requires Patch 1, you must check in Patch 1 before Patch 2. Packages cannot be reordered once they are checked in. You must remove them and check them in again, in the proper order. If you check in a package that supersedes an existing package, the existing package is removed automatically.