McAfee EPOCDE-AA-BA Product Guide - Page 37

SSL certificates, Replacing the server certificate

Page 37 highlights

Configuring general server settings Configuring general server settings 4 Task For option definitions, click ? in the interface. 1 Click Menu | Configuration | Server Settings, select Proxy Settings from the Setting Categories, then click Edit. 2 Select Configure the proxy settings manually, provide the specific configuration information your proxy server uses for each set of options, then click Save. SSL certificates The browsers supported by McAfee ePO show a warning about a server's SSL certificate if it cannot verify that the certificate is valid or signed by a source that the browser trusts. By default, the McAfee ePO server uses a self-signed certificate for SSL communication with the web browser, which, by default, the browser will not trust. This causes a warning message to display every time you visit the McAfee ePO console. To stop this warning message from appearing you must do one of the following: • Add the McAfee ePO server certificate to the collection of trusted certificates used by the browser. This must be done for every browser that interacts with McAfee ePO. If the browser certificate changes, you must add the McAfee ePO server certificate again since the certificate sent by the server no longer matches the one that the browser is configured to use. • Replace the default McAfee ePO server certificate with a valid certificate that has been signed by a certificate authority (CA) that the browser trusts. This is the best option. Because the certificate is signed by a trusted CA, you do not need to add the certificate to all web browsers within your organization. If the server host name changes, you can replace the server certificate with a different one that has also been signed by a trusted CA. To replace the McAfee ePO server certificate, you must first obtain the certificate - preferably a certificate that has been signed by a trusted CA. You must also obtain the certificate's private key and its password (if it has one). Then you can use all of these files to replace the server's certificate. For more information on replacing server certificates, see Security keys and how they work. The McAfee ePO browser expects the linked files to use the following format: • Server certificate - P7B or PEM • Private key - PEM If the server certificate or private key are not in these formats, they must be converted to one of the supported formats before they can be used to replace the server certificate. Replacing the server certificate Use this task to specify the server certificate and private key used by ePolicy Orchestrator. For option definitions, click ? in the interface. Task 1 Click Menu | Configuration | Server Settings, then click Server Certificate in the Settings Categories list. 2 Click Edit. The Edit Server Certificate page appears. 3 Browse to the server certificate file and click Open. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Task
For option definitions, click
?
in the interface.
1
Click
Menu
|
Configuration
|
Server Settings
, select
Proxy Settings
from the
Setting Categories
, then click
Edit
.
2
Select
Configure the proxy settings manually
, provide the specific configuration information your proxy
server uses for each set of options, then click
Save
.
SSL certificates
The browsers supported by McAfee ePO show a warning about a server’s SSL certificate if it cannot
verify that the certificate is valid or signed by a source that the browser trusts. By default, the McAfee
ePO server uses a self-signed certificate for SSL communication with the web browser, which, by
default, the browser will not trust. This causes a warning message to display every time you visit the
McAfee ePO console.
To stop this warning message from appearing you must do one of the following:
Add the McAfee ePO server certificate to the collection of trusted certificates used by the browser.
This must be done for every browser that interacts with McAfee ePO. If
the browser certificate changes, you must add the McAfee ePO server
certificate again since the certificate sent by the server no longer
matches the one that the browser is configured to use.
Replace the default McAfee ePO server certificate with a valid certificate that has been signed by a
certificate authority (CA) that the browser trusts. This is the best option. Because the certificate is
signed by a trusted CA, you do not need to add the certificate to all web browsers within your
organization.
If the server host name changes, you can replace the server certificate
with a different one that has also been signed by a trusted CA.
To replace the McAfee ePO server certificate, you must first obtain the certificate — preferably a
certificate that has been signed by a trusted CA. You must also obtain the certificate’s private key and
its password (if it has one). Then you can use all of these files to replace the server’s certificate. For
more information on replacing server certificates, see
Security keys and how they work
.
The McAfee ePO browser expects the linked files to use the following format:
Server certificate — P7B or PEM
Private key — PEM
If the server certificate or private key are not in these formats, they must be converted to one of the
supported formats before they can be used to replace the server certificate.
Replacing the server certificate
Use this task to specify the server certificate and private key used by ePolicy Orchestrator.
For option definitions, click
?
in the interface.
Task
1
Click
Menu
|
Configuration
|
Server Settings
, then click
Server Certificate
in the Settings Categories list.
2
Click
Edit
. The Edit Server Certificate page appears.
3
Browse to the server certificate file and click
Open
.
Configuring general server settings
Configuring general server settings
4
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
37