I have created a custom SSL certificate that is issued to the published DNS name with some SANs added to it. I have followed the steps mentioned as in KB article located at
https://kc.mcafee.com/corporate/index?page=content&id=KB72477
and there is no error till I upload it.
After uploading the certificate to ePO, the browser says it is invalid.
The certificate is issued to ePO.companyname.com and agents can reach to this address as well. Also, is there a way to change the URL link to
ePO.companyname.com:8443/core/orionSplashScreen.do?
Thanks in advance.
Trellix ePolicy Orchestrator
Solved! Go to Solution.
The orion log is what you should be looking at. You may have to stop all epo services to edit the shortcut file.
The only thing I can suggest is to either open a ticket with McAfee, or send me your certificate so I can check it out. I will send you private message.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Does the cert have the root cert for your CA in the certificate chain? Are you using the private key you generated originally in the KB to import (after removing password)?
Yes, you can change the url.
In the root of the epo install directory, you will see a file called shortcut - full name is shortcut.url. Go to properties of that file and change the url to the fqdn of the server.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Also, does it give any other errors besides invalid? Does the orion log show anything? That is in the server\logs directory where epo is installed.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Q. Does the cert have the root cert for your CA in the certificate chain? Are you using the private key you generated originally in the KB to import (after removing password)?
A. Yes, the certificate chain contains the root certificate which was added using this command mentioned in KB,
openssl> crl2pkcs7 -nocrl -certfile rootcertificate.crt -certfile certificatenew.crt -out epoupload.p7b
I uploaded a new key "unsecured.mcafee.key"file after removing the password by using this command as well.
openssl> rsa -in mcafee.key -out unsecured.mcafee.key
And to add the fqdn I tried to edit the mentioned shortcut.url file but the file can't be modified.
The message is cannot apply changes to this internet shortcut. I tried to copy edited shortcut file after adding fqdn to another location. The replacement of original shortcut.url with the modified one was successful but if I open the pasted file to the ePO installed folder there are no changes.
Q. Also, does it give any other errors besides invalid? Does the orion log show anything? That is in the server\logs directory where epo is installed.
A. I checked the log file called "localhost_access_log.log" and inside that the file is full of text
"[07/May/2020:00:00:46 -0500] 0:0:0:0:0:0:0:1 POST /dcRedirect/dataChannelMsg.dc HTTP/1.1 - 200 [http-nio-8444-exec-17] [-] 0ms"
The orion log is what you should be looking at. You may have to stop all epo services to edit the shortcut file.
The only thing I can suggest is to either open a ticket with McAfee, or send me your certificate so I can check it out. I will send you private message.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: