McAfee EPOLICY ORCHESTRATOR 4.5 Product Manual page 49

Hide thumbs Also See for EPOLICY ORCHESTRATOR 4.5:
Table of Contents

Advertisement

Configuring ePolicy Orchestrator
Security keys and how they work
Process overview
TIP:
If you have a large number of managed systems in your environment, McAfee recommends
performing this process in phases so you can monitor agent updates.
1
Create an agent update task.
2
Export the keys chosen from the selected ePO server.
3
Import the exported keys to all other servers.
4
Designate the imported key as the master on all servers.
5
Perform two agent wake-up calls
6
When all agents are using the new keys, delete any unused keys.
7
Back up all keys.
NOTE:
Ensure that the agent key updater package is checked in to the master repository and
has been replicated to all distributed repositories that are managed by ePolicy Orchestrator.
Agents begin using the new key pair after the next update task for the agent is complete. At
any time, you can see which agents are using any of the agent-server secure communication
key pairs in the list.
Using a different ASSC key pair for each ePO server
Use this task to ensure that all agents can communicate with the required ePO servers in an
environment where each ePO server must have a unique agent-server secure communication
key pair.
NOTE:
Agents can communicate with only one server at a time. The ePO server can have
multiple keys to communicate with different agents, but the opposite is not true. Agents cannot
have multiple keys to communicate with multiple ePO servers.
Task
For option definitions, click ? in the interface.
1
From each ePO server in your environment, export the master agent-server secure
communication key pair to a temporary location to where? a location? a zip file?.
2
Import each of these key pairs into every ePO server.
Viewing systems that use an ASSC key pair
Use this task to view the systems whose agents use a specific agent-server secure communication
key pair, which appears in the Agent-server secure communication keys list. After making
a specific key pair the master, you might want to view the systems that are still using the
previous key pair. Do not delete a key pair until you know that no agents are still using it.
Task
For option definitions, click ? in the interface.
1
Click Menu | Configuration | Server Settings, select Security Keys from the Setting
Categories list, then click Edit. The Edit Security Keys page appears.
2
In the Agent-server secure communication keys list, select a key, then click View
Agents. The Systems using this key page appears.
This page lists all systems whose agents are using the selected key.
McAfee ePolicy Orchestrator 4.5 Product Guide
49

Advertisement

Table of Contents
loading

Table of Contents