Migrating root certificate to 3072-bit key

Prev Next

To improve security in the cryptographic systems, migrate the root certificates from a 2048-bit to a 3072-bit in ePO - On-prem.

Before you begin, make sure your system meets these requirements:

  • Trellix ePO 5.10.0 Service Pack 1 Update 3

  • Trellix Agent 5.8.3 and later

  • Trellix DXL Broker 6.0.5 and later.

  1. Navigate to MenuConfigurationCertification Manager.

    The Key Size of root certificate displays 2048.

  2. Click Regenerate Certificate and click OK to start the regeneration.

    The time needed to generate the new certificates varies depending on the number of Agent Handlers and Extensions that derive certificates from the ePO root CA.

    Note

    Before you move to next step, ensure that all targeted systems have communicated with ePO - On-prem. Otherwise, these systems may not receive the newly generated certificates, leading to communication issues with ePO - On-prem after migration.

  3. Perform Wakeup Agent to ensure that the endpoint's status reaches 100% upon receiving the newly generated certificate.

  4. In Certificate Manager, go to Product: Agent HandlerStatus and check if the percentage of agents that have received the newly-generated certificates is 100%. If the status is not 100%, click the link and complete the processing.

  5. Click Activate Certificate.

  6. (Mandatory) Restart both ePO - On-prem and the Agent Handler services to apply the changes. For more information on best practices for migration, see KB87017.

  7. Perform Wakeup Agent to ensure that the endpoint's status reaches 100% upon receiving the newly generated certificate.

  8. Click Finish Migration.

    In case you want to cancel the migration, click Cancel Migration and then restart both Trellix ePO and the Agent Handler services.

  9. (Mandatory) Restart both ePO - On-prem and the Agent Handler services to apply the changes. For more information on best practices for migration, see KB87017.

Verify post-migration changes

  1. In Certificate Manager page, check if all the products and root certificate display Key Size as 3072.

  2. Perform Wakeup Agent or ASCII from endpoint/client to confirm the communication is working as expected.

  3. Login to the Client machine and go to the location - C:\programdata\McAfee\Agent. Open the cabundle certificate and navigate to the Details Tab. Check if the Public Key Size is changed to 3072 after the first agent-server communication post migration.

  4. Open the cabundle certificate and go to the Details tab. Check that the Public Key Size has changed to 3072 after the first agent-server communication following the certificate regeneration.