McAfee EPOCDE-AA-BA - ePolicy Orchestrator - PC Product Manual page 66

Product guide
Table of Contents

Advertisement

7
Configuring advanced server settings
Managing security keys
Tasks
Using one master repository key pair for all servers on page 66
Use this task to ensure that all McAfee ePO servers and agents use the same master
repository key pair in a multi-server environment.
Using master repository keys in multi-server environments on page 66
Use this task to ensure that agents can use content originating from any McAfee ePO server
in your environment.
Using one master repository key pair for all servers
Use this task to ensure that all McAfee ePO servers and agents use the same master repository key
pair in a multi-server environment.
This consists of first exporting the key pair you want all servers to use, then importing the key pair
into all other servers in your environment.
Task
For option definitions, click ? in the interface.
Click Menu | Configuration | Server Settings, select Security Keys from the Setting Categories list, then click
1
Edit.
The Edit Security Keys page appears.
Next to Local master repository key pair, click Export Key Pair.
2
The Export Master Repository Key Pair dialog box appears.
Click OK. The File Download dialog box appears.
3
Click Save, browse to a location that is accessible by the other servers, where you want to save the
4
zip file containing the secure-communication key files, then click Save.
Next to Import and back up keys, click Import .
5
The Import Keys wizard opens.
Browse to the zip file containing the exported master repository key files, then click Next.
6
7
Verify that these are the keys you want to import, then click Save.
The imported master repository key pair replaces the existing key pair on this server. Agents begin
using the new key pair after the next agent update task runs. Once the master repository key pair is
changed, an ASSC must be performed before the agent can use the new key.
Using master repository keys in multi-server environments
Use this task to ensure that agents can use content originating from any McAfee ePO server in your
environment.
The server signs all unsigned content that is checked in to the repository with the master repository
private key. Agents use repository public keys to validate content that is retrieved from repositories in
your organization or from McAfee source sites.
The master repository key pair is unique for each installation of ePolicy Orchestrator. If you use
multiple servers, each uses a different key. If your agents can download content that originates from
different master repositories, you must ensure that agents recognize the content as valid.
You can ensure this in two ways:
Use the same master repository key pair for all servers and agents.
Ensure agents are configured to recognize any repository public key that is used in your environment.
®
66
McAfee
ePolicy Orchestrator
®
4.6.0 Software Product Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Epolicy orchestrator 4.6.0

Table of Contents