Generating self-signed certificate

Prev Next

Trellix Logon Collector communicates with a two-way SSL authentication. It requires an exchange of certificate between the NDR and TLC server.

To generate self-sign certificate:

  1. On the Configure TLC page, type G and then press Enter to generate a self-signed certificate.

  2. Generating RSA private key:

    1. The appliance generates /root/ca/cakey.pem and /root/ca/cacert.pem RSA keys and will request you to provide the PEM pass phrase.

    2. Type PEM pass phrase in the Enter PEM pass phrase field and then press Enter.

    3. Provide all the necessary information to be included in your certificate and then press Enter. Keystore keys are generated.

  3. Uploading self-signed certificate in TLC Server:

    1. Click the browse icon and navigate to the the Configuration > Trusted CAs > New Authority and select the Base 64 Encoded option and then paste the self signed certificate in the box.

    2. Click Save.

  4. Configuring IP/FQDN and port.

    1. Type C to configure IP/FQDN and port.

    2. In the Enter IP port separated by colon field, type the IP address and then press Enter.

      Use this format "<IP:Port>" for configuring TLC server. Example: "172.16.14.28:61641".

      Note

      Always use the default TCP port "61641".

    To enable/disable/reset /regernerate TLC certificate:

    1. Type E to enable or disable the tlc feature.

    2. Type R to reset TLC certificate. Type yes to re-upload the file.

    3. In the Enter tlc file name field, type the tlc file name that you want to upload. A message indicates that the new file has been uploaded successfully to keystore. Press Enter. In the Enter IP port separated by colon field, type the IP address and then press Enter.

    4. Type H if you want to regenerate self-signed certificate.

    5. Type S to display the self-signed certificate. Press Enter.

    6. Type D to disconnect TLC Server. All the tlc related configs and certificates are deleted.

  5. Type Q to quit the menu.