McAfee EPOCDE-AA-BA Product Guide - Page 66

Using one master repository key pair for all servers

Page 66 highlights

7 Configuring advanced server settings Managing security keys Tasks • Using one master repository key pair for all servers on page 66 Use this task to ensure that all McAfee ePO servers and agents use the same master repository key pair in a multi-server environment. • Using master repository keys in multi-server environments on page 66 Use this task to ensure that agents can use content originating from any McAfee ePO server in your environment. Using one master repository key pair for all servers Use this task to ensure that all McAfee ePO servers and agents use the same master repository key pair in a multi-server environment. This consists of first exporting the key pair you want all servers to use, then importing the key pair into all other servers in your environment. Task For option definitions, click ? in the interface. 1 Click Menu | Configuration | Server Settings, select Security Keys from the Setting Categories list, then click Edit. The Edit Security Keys page appears. 2 Next to Local master repository key pair, click Export Key Pair. The Export Master Repository Key Pair dialog box appears. 3 Click OK. The File Download dialog box appears. 4 Click Save, browse to a location that is accessible by the other servers, where you want to save the zip file containing the secure-communication key files, then click Save. 5 Next to Import and back up keys, click Import . The Import Keys wizard opens. 6 Browse to the zip file containing the exported master repository key files, then click Next. 7 Verify that these are the keys you want to import, then click Save. The imported master repository key pair replaces the existing key pair on this server. Agents begin using the new key pair after the next agent update task runs. Once the master repository key pair is changed, an ASSC must be performed before the agent can use the new key. Using master repository keys in multi-server environments Use this task to ensure that agents can use content originating from any McAfee ePO server in your environment. The server signs all unsigned content that is checked in to the repository with the master repository private key. Agents use repository public keys to validate content that is retrieved from repositories in your organization or from McAfee source sites. The master repository key pair is unique for each installation of ePolicy Orchestrator. If you use multiple servers, each uses a different key. If your agents can download content that originates from different master repositories, you must ensure that agents recognize the content as valid. You can ensure this in two ways: • Use the same master repository key pair for all servers and agents. • Ensure agents are configured to recognize any repository public key that is used in your environment. 66 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Tasks
Using one master repository key pair for all servers
on page 66
Use this task to ensure that all McAfee ePO servers and agents use the same master
repository key pair in a multi-server environment.
Using master repository keys in multi-server environments
on page 66
Use this task to ensure that agents can use content originating from any McAfee ePO server
in your environment.
Using one master repository key pair for all servers
Use this task to ensure that all McAfee ePO servers and agents use the same master repository key
pair in a multi-server environment.
This consists of first exporting the key pair you want all servers to use, then importing the key pair
into all other servers in your environment.
Task
For option definitions, click
?
in the interface.
1
Click
Menu
|
Configuration
|
Server Settings
, select
Security Keys
from the Setting Categories list, then click
Edit
.
The Edit Security Keys page appears.
2
Next to
Local master repository key pair
, click
Export Key Pair
.
The Export Master Repository Key Pair dialog box appears.
3
Click
OK
. The File Download dialog box appears.
4
Click
Save
, browse to a location that is accessible by the other servers, where you want to save the
zip file containing the secure-communication key files, then click
Save
.
5
Next to
Import and back up keys
, click
Import
.
The Import Keys wizard opens.
6
Browse to the zip file containing the exported master repository key files, then click
Next
.
7
Verify that these are the keys you want to import, then click
Save
.
The imported master repository key pair replaces the existing key pair on this server. Agents begin
using the new key pair after the next agent update task runs. Once the master repository key pair is
changed, an ASSC must be performed before the agent can use the new key.
Using master repository keys in multi-server environments
Use this task to ensure that agents can use content originating from any McAfee ePO server in your
environment.
The server signs all unsigned content that is checked in to the repository with the master repository
private key. Agents use repository public keys to validate content that is retrieved from repositories in
your organization or from McAfee source sites.
The master repository key pair is unique for each installation of ePolicy Orchestrator. If you use
multiple servers, each uses a different key. If your agents can download content that originates from
different master repositories, you must ensure that agents recognize the content as valid.
You can ensure this in two ways:
Use the same master repository key pair for all servers and agents.
Ensure agents are configured to recognize any repository public key that is used in your environment.
7
Configuring advanced server settings
Managing security keys
66
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide