Trellix Logon Collector communicates with a two-way SSL authentication. It requires an exchange of certificate between the NDR and TLC server.
To generate self-sign certificate:
On the Configure TLC page, type
Gand then pressEnterto generate a self-signed certificate.Generating RSA private key:
The appliance generates
/root/ca/cakey.pemand/root/ca/cacert.pemRSA keys and will request you to provide the PEM pass phrase.Type PEM pass phrase in the
Enter PEM pass phrasefield and then pressEnter.Provide all the necessary information to be included in your certificate and then press
Enter. Keystore keys are generated.
Uploading self-signed certificate in TLC Server:
Click the browse icon and navigate to the the Configuration > Trusted CAs > New Authority and select the Base 64 Encoded option and then paste the self signed certificate in the box.
Click Save.
Configuring IP/FQDN and port.
Type
Cto configure IP/FQDN and port.In the
Enter IP port separated by colonfield, type the IP address and then pressEnter.Use this format "<IP:Port>" for configuring TLC server. Example: "172.16.14.28:61641".
Note
Always use the default TCP port "61641".
To enable/disable/reset /regernerate TLC certificate:
Type
Eto enable or disable the tlc feature.Type
Rto reset TLC certificate. Typeyesto re-upload the file.In the
Enter tlc file namefield, type the tlc file name that you want to upload. A message indicates that the new file has been uploaded successfully to keystore. PressEnter. In theEnter IP port separated by colonfield, type the IP address and then pressEnter.Type
Hif you want to regenerate self-signed certificate.Type
Sto display the self-signed certificate. PressEnter.Type
Dto disconnect TLC Server. All the tlc related configs and certificates are deleted.
Type
Qto quit the menu.