McAfee EPOCDE-AA-BA Product Guide - Page 67

Agent-server secure communication (ASSC) keys, Working with ASSC keys

Page 67 highlights

Configuring advanced server settings Managing security keys 7 The following process exports the key pair from one McAfee ePO server to a target McAfee ePO server, then, at the target McAfee ePO server, imports and overwrites the existing key pair. For option definitions, click ? in the interface. Task 1 On the McAfee ePO server with the master repository key pair, click Menu | Configuration | Server Settings, select Security Keys from the Setting Categories list, then click Edit. The Edit Security Keys page appears. 2 Next to Local master repository key pair, click Export Key Pair. The Export Master Repository Key Pair dialog box appears. 3 Click OK. The File Download dialog box appears. 4 Click Save, then browse to a location on the target McAfee ePO server to save the zip file. 5 Change the name of the file if needed, then click Save. 6 On the target McAfee ePO server where you want to load the master repository key pair, click Menu | Configuration | Server Settings, select Security Keys from the Setting Categories list, then click Edit. The Edit Security Keys page appears. 7 Next to Import and back up keys, click Import. The Import Keys dialog box appears. 8 Next to Select file, browse to and select the master key pair file you saved, then click Next. The summary dialog box appears. 9 If the summary information appears correct, click Save. The new master key pair appears in the list next to Agent-server secure communication keys. 10 From the list, select the file you imported in the previous steps and click Make Master. This changes the existing master key pair to the new key pair you just imported. 11 Click Save to complete the process. Agent-server secure communication (ASSC) keys Agent-server secure communication (ASSC) keys are used by the agents to communicate securely with the server. You can make any ASSC key pair the master, which is the key pair currently assigned to all deployed agents. Existing agents that use other keys in the Agent-server secure communication keys list do not change to the new master key unless there is a client agent key updater task scheduled and run. Be sure to wait until all agents have updated to the new master before deleting older keys. Windows agents older than version 3.6 are not supported. Working with ASSC keys Use these tasks to work with and manage ASSC keys in your environment. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 67

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

The following process exports the key pair from one McAfee ePO server to a target McAfee ePO server,
then, at the target McAfee ePO server, imports and overwrites the existing key pair.
For option definitions, click
?
in the interface.
Task
1
On the McAfee ePO server with the master repository key pair, click
Menu
|
Configuration
|
Server
Settings
, select
Security Keys
from the Setting Categories list, then click
Edit
.
The Edit Security Keys page appears.
2
Next to
Local master repository key pair
, click
Export Key Pair
.
The Export Master Repository Key Pair dialog box appears.
3
Click
OK
.
The File Download dialog box appears.
4
Click
Save
, then browse to a location on the target McAfee ePO server to save the zip file.
5
Change the name of the file if needed, then click
Save
.
6
On the target McAfee ePO server where you want to load the master repository key pair, click
Menu
|
Configuration
|
Server Settings
, select
Security Keys
from the Setting Categories list, then click
Edit
.
The Edit Security Keys page appears.
7
Next to
Import and back up keys
, click
Import
.
The Import Keys dialog box appears.
8
Next to
Select file
, browse to and select the master key pair file you saved, then click
Next
.
The summary dialog box appears.
9
If the summary information appears correct, click
Save
. The new master key pair appears in the list
next to
Agent-server secure communication keys
.
10
From the list, select the file you imported in the previous steps and click
Make Master
. This changes
the existing master key pair to the new key pair you just imported.
11
Click
Save
to complete the process.
Agent-server secure communication (ASSC) keys
Agent-server secure communication (ASSC) keys are used by the agents to communicate securely
with the server.
You can make any ASSC key pair the master, which is the key pair currently assigned to all deployed
agents. Existing agents that use other keys in the
Agent-server secure communication keys
list do not change
to the new master key unless there is a client agent key updater task scheduled and run.
Be sure to wait until all agents have updated to the new master before
deleting older keys.
Windows agents older than version 3.6 are not supported.
Working with ASSC keys
Use these tasks to work with and manage ASSC keys in your environment.
Configuring advanced server settings
Managing security keys
7
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
67