To remediate vulnerabilities in your ePO - On-prem environment, migrate your existing certificates to more secure algorithm certificates or regenerate them.
The SHA-1 algorithm has reached end-of-life (EOL). Many organizations are deprecating TLS/SSL certificates signed by the SHA-1 algorithm. If you continue to use SHA-1 certificates, browsers such as Google Chrome or Microsoft Internet Explorer will flag the ePO - On-prem console as an unsecure HTTPS site.
If you have upgraded ePO - On-prem from an older version, migrate ePO - On-prem certificates to the latest hash algorithm. A fresh installation of ePO - On-prem installs the latest hash algorithm certificates.
The Certificate Manager allows you to:
Migrate certificates that are signed by older signing algorithm to the new algorithm such as SHA-1 to SHA-256.
Regenerate your certificates when your existing certificates are compromised due to vulnerabilities in your environment.
Migrate or regenerate certificates for managed products that are derived from ePO - On-prem root CA.
This task replaces certificates that are used for:
Agent-server communication
Authenticating to browsers
Certificate-based user authentication
Important
Read these instructions carefully before proceeding with the steps. If you activate the new certificates before they are populated on the systems in your network, those systems won't be able to connect to your ePO - On-prem server until the agents on those systems are re-installed.
For details about product features, usage, and best practices, click ? or Help.
Log on as an administrator, then select Menu → Configuration → Certificate Manager.
The Certificate Manager page provides information about the installed Root Certificate, Agent Handler certificates, server certificates, and other certificates that are derived from ePO - On-prem root Certificate Authority (CA).
Click Regenerate Certificate, then click OK to confirm.
The ePO - On-prem root CA and other certificates that are derived from the root CA are regenerated and stored in a temporary location on the server. The time required to complete the process depends on the number of Agent Handlers and extensions that derive certificates from ePO - On-prem root CA.
Note
When regenerating Agent Handler leaf certificates, you can specify custom Subject Alternative Names (SANs) by appending the <
SAN values> parameter to the certificate generation command line. If omitted, the system automatically uses the host FQDN as the default SAN while preserving the Common Name (CN).After the certificates regenerate, wait for sufficient saturation of the new certificates throughout your environment.
As agents communicate to the ePO - On-prem server, they are given the new certificate. The percentage of agents that have received the newly-generated certificates is provided in the Certificate Manager under Product: Agent Handler → Status.
Important
Make sure that the distribution percentage is as close to 100% as possible before you continue. Otherwise, pending systems might not receive the newly generated certificates and won't be able to communicate with the ePO - On-prem after the certificates are activated. You can stay in this state for as long as is necessary to achieve sufficient saturation.
Once you've achieved a distribution percentage close to 100%, click Activate Certificates to carry out all future operations using the new certificates.
A backup of the original certificates is created, and a message appears.
Click OK.
Stop and start these services:
Stop the Agent Handler services.
Restart the ePO - On-prem services.
Start the Agent Handler services.
Monitor your environment and make sure that your agents are successfully communicating.
You can cancel the migration at this point to roll back the certificate and restore agent-to-server communication; however, this is not possible after you have completed the next step.
Click Finish Migration to complete the certificate migration.
For any issues during the migration, click Cancel Migration to revert to the previous certificates. If you cancel the migration, stop the Agent Handler services, restart the ePO - On-prem service, and start the Agent Handler service again.
You can start the certificate migration again after fixing any issues.
Re-install any agents that use the old certificates to restore agent-server communication.