Manage ASSC keys

Prev Next

Generate, export, import, or delete agent-server secure communication (ASSC) keys from the Server Settings page.

For details about product features, usage, and best practices, click ? or Help.

  1. Select MenuConfigurationServer Settings, select Security Keys, then click Edit.

  2. Select one of these actions.

    Action

    Steps

    Generate and use new ASSC key pairs

    1. Next to the Agent-server secure communication keys list, click New Key. In the dialog box, type the name of the security key.

    2. If you want existing agents to use the new key, select the key in the list, then click Make main. Agents begin using the new key after the next Trellix Agent update task is complete.

      Make sure that there is an Agent Key Updater package for each version of the Trellix Agent managed by ePO - On-prem.

      Caution

      In large installations, only generate and use new main key pairs when you have specific reason to do so. We recommend performing this procedure in phases so that you can more closely monitor progress.

    3. After all agents have stopped using the old key, delete it.

      In the list of keys, the number of agents currently using that key is displayed to the right of every key.

    4. Back up all keys.

    Export ASSC keys

    Export ASSC keys from one ePO - On-prem server to a different ePO - On-prem server, to allow agents to access the new ePO - On-prem server.

    1. In the Agent-server secure communication keys list, select a key, then click Export.

    2. Click OK.

      Your browser prompts you to download the sr<ServerName>.zip file to the specified location.

      Note

      If you specified a default location for all browser downloads, this file might be automatically saved to that location.

    Import ASSC keys

    Import ASSC keys that were exported from a different ePO - On-prem server, allowing agents from that server to access this ePO - On-prem server.

    1. Click Import.

    2. Browse to and select the key from the location where you saved it (by default, on the desktop), then click Open.

    3. Click Next and review the information about the Import Keys page.

    4. Click Save.

    Designate an ASSC key pair as the main

    Change which key pair is specified as the main. Specify a main key pair after importing or generating a new key pair.

    1. From the Agent-server secure communication keys list, select a key, then click Make main.

    2. Create an update task for the agents to run immediately, so that agents update after the next agent-server communication.

      Note

      Make sure that the Agent Key Updater package is checked in to the ePO - On-prem main Repository. Agents begin using the new key pair after the next update task for the Trellix Agent is complete. At any time, you can see which agents are using any of the ASSC key pairs in the list.

    3. Back up all keys.

    Delete ASSC keys

    Caution

    Do not delete any keys that are being used by any agents. If you do, those agents cannot communicate with the ePO - On-prem server.

    1. From the Agent-server secure communication keys list, select the key that you want to remove, then click Delete.

    2. Click OK to delete the key pair from this server.