msm common certs deploy

Prev Next

Use this command to deploy the MTP SSL certificates from the staging directory into the operational directory and then reboot the MX Series appliance so that the new certificates take effect.

In order for the command to succeed, the SSL authentication items must meet the following requirements:

  • The SSL certificate must be a .pem file. If the certificate is a Microsoft .p12 or .pfx file, convert the file to PEM format.

  • The public key in the certificate must match the public portion of the private key.

  • If the SSL certificate is signed by a trusted third-party CA (as is required for ether1), verify that the SSL chain includes all intermediate certificates, from host certificate to root CA. If the CA bundle is not in correct chain order, re-order the certificates.

Important

If the command fails, the system does not deploy the certificate to the truststore, and the appliance does not reboot. After you correct the problem, upload the corrected SSL authentication items to staging, and deploy the corrected certificate to the SSL truststore.

Syntax

msm common certs deploy

Parameters

None

Examples

After you use the Settings > SSL Certificates page of the Web UI to upload SSL authentication items for ether1 or ether2 to the MX Series appliance staging directory, deploy and activate the SSL certificates:

hostname (configure) # msm common certs deploy

For more information, see the Trellix MTP Management Appliance System Configuration Guide.

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security:Trellix MTP Management Appliance Release 2.0.1.