Backing Up And Restoring Keys - McAfee EPOLICY ORCHESTRATOR 4.5 Product Manual

Hide thumbs Also See for EPOLICY ORCHESTRATOR 4.5:
Table of Contents

Advertisement

Configuring ePolicy Orchestrator
Security keys and how they work
Agent-server secure communication (ASSC) keys
• The first time the agent communicates with the server, it sends its public key to the server.
• From then on, the server uses the agent public key to verify messages signed with the
agent's secret key.
• The server uses its own secret key to sign its message to the agent.
• The agent uses the server's public key to verify the agent's message.
• You can have multiple secure communication key pairs, but only one can be designated as
the master key .
• When the client agent key updater task runs (ePO Agent Key Updater 3.5.5), agents
using different public keys receive the current public key.
• If you are upgrading from ePolicy Orchestrator 3.6 or earlier, a legacy key is retained. If
you are upgrading from ePolicy Orchestrator 3.6.1, the legacy key is the master key by
default. If you are upgrading from ePolicy Orchestrator 4.0, the master key is unchanged.
Whether or not you upgrade from version 3.6.1 or 4.0, the existing keys are migrated to
your ePO 4.5 server.
Local master repository key pairs
• The repository secret key signs the package before it is checked in to the repository.
• The repository public key verifies the contents of packages in the master repository and
distributed repository.
• The agent retrieves available new content each time the client update task runs.
• This key pair is unique to each server.
• By exporting and importing keys among servers, you can use the same key pair in a
multi-server environment.
Other repository key pairs
• The secret key of a trusted source signs its content when posting that content to its remote
repository. Trusted sources include the McAfee download site and the McAfee Security
Innovation Alliance (SIA) repository.
CAUTION:
another server. Before you overwrite or delete this key, make sure to back it up in a secure
location.
• The agent public key verifies content that is retrieved from the remote repository.

Backing up and restoring keys

Use these tasks to back up and restore security keys.
Tasks
Backing up all security keys
Restoring security keys
Restoring security keys from a backup file
42
McAfee ePolicy Orchestrator 4.5 Product Guide
If this key is deleted, you cannot perform a pull, even if you import a key from

Advertisement

Table of Contents
loading

Table of Contents