McAfee EPOCDE-AA-BA Product Guide - Page 70

Designating an ASSC key pair as the master, Using the same ASSC key pair for all servers and agents

Page 70 highlights

7 Configuring advanced server settings Managing security keys 3 If you want existing agents to use the new key, select the key in the list, then click Make Master. Agents begin using the new key after the next agent update task is complete. If the server manages 4.6 agents, make sure the 4.6 Agent Key Updater package has been checked into the master repository. In large installations, generating and using new master key pairs should be performed only when you have specific reason to do so. McAfee recommends performing this procedure in phases so you can more closely monitor progress. 4 After all agents have stopped using the old key, delete it. In the list of keys, the number of agents currently using that key is displayed to the right of every key. 5 Back up all keys. Designating an ASSC key pair as the master Use this task to change which key pair, listed in the Agent-server secure communication keys list, is specified as the master. Do this after importing or generating a new key pair. For option definitions, click ? in the interface. Task 1 Click Menu | Configuration | Server Settings, select Security Keys from the Setting Categories list, then click Edit. The Edit Security Keys page appears. 2 From the Agent-server secure communication keys list, select a key , then click Make Master. 3 Create an update task for the agents to run immediately, so that agents update after the next agent-server communication. Ensure that the agent key updater package is checked in to the master repository and has been replicated to all distributed repositories that are managed by ePolicy Orchestrator. Agents begin using the new key pair after the next update task for the agent is complete. At any time, you can see which agents are using any of the agent-server secure communication key pairs in the list. 4 Back up all keys. Using the same ASSC key pair for all servers and agents Follow this process to ensure that all McAfee ePO servers and agents use the same agent-server secure communication (ASSC) key pair. If you have a large number of managed systems in your environment, McAfee recommends performing this process in phases so you can monitor agent updates. 1 Create an agent update task. 2 Export the keys chosen from the selected McAfee ePO server. 3 Import the exported keys to all other servers. 4 Designate the imported key as the master on all servers. 5 Perform two agent wake-up calls 70 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

3
If you want existing agents to use the new key, select the key in the list, then click
Make Master
.
Agents begin using the new key after the next agent update task is complete. If the server
manages 4.6 agents, make sure the 4.6 Agent Key Updater package has been checked into the
master repository.
In large installations, generating and using new master key pairs should
be performed only when you have specific reason to do so. McAfee
recommends performing this procedure in phases so you can more
closely monitor progress.
4
After all agents have stopped using the old key, delete it.
In the list of keys, the number of agents currently using that key is displayed to the right of every
key.
5
Back up all keys.
Designating an ASSC key pair as the master
Use this task to change which key pair, listed in the
Agent-server secure communication keys
list, is specified
as the master. Do this after importing or generating a new key pair.
For option definitions, click
?
in the interface.
Task
1
Click
Menu
|
Configuration
|
Server Settings
, select
Security Keys
from the Setting Categories list, then click
Edit
.
The Edit Security Keys page appears.
2
From the
Agent-server secure communication keys
list, select a key , then click
Make Master
.
3
Create an update task for the agents to run immediately, so that agents update after the next
agent-server communication.
Ensure that the agent key updater package is checked in to the master
repository and has been replicated to all distributed repositories that are
managed by ePolicy Orchestrator. Agents begin using the new key pair
after the next update task for the agent is complete. At any time, you
can see which agents are using any of the agent-server secure
communication key pairs in the list.
4
Back up all keys.
Using the same ASSC key pair for all servers and agents
Follow this process to ensure that all McAfee ePO servers and agents use the same agent-server
secure communication (ASSC) key pair.
If you have a large number of managed systems in your environment,
McAfee recommends performing this process in phases so you can
monitor agent updates.
1
Create an agent update task.
2
Export the keys chosen from the selected McAfee ePO server.
3
Import the exported keys to all other servers.
4
Designate the imported key as the master on all servers.
5
Perform two agent wake-up calls
7
Configuring advanced server settings
Managing security keys
70
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide