Summary
This KB article deals with: How to configure Unix-based (AIX, HP-UX, Linux, MacOS, Solaris) Managed Devices to communicate over HTTPS (SSL/TLS).Synopsis
In some instances it is require to allow Unix-based systems (AIX, HP-UX, Linux, MacOS, Solaris) to communicate over HTTPS (SSL/TLS) using a certificate when uploading and downloading inventory and polices among other actions.Discussion
The following steps should allow the configuration of trusted certificates for use with the above managed devices:
- Obtain a copy of all root Certificate Authority (CA) certificates
that are used by your HTTPS web servers. For most organisations, this
will be a single certificate. The certificate should be saved using
the PEM format.
- The PEM format certificates should be base-64 encoded plain text
surrounded by a "BEGIN CERTIFICATE" header and an "END CERTIFICATE"
footer. That is for example:
-----BEGIN CERTIFICATE-----
MIIDiTCCAnGgAwIBAgIQWO/IibrLpZ5Hts3u3xH7TzANBgkqhkiG9w0BAQUFADAR
MQ8wDQYDVQQDEwZ0ZncyazMwHhcNMTAxMTI1MDEyMDM4WhcNMTUxMTI1MDEyODA1
......
wXvMSERKsNsJ6FwwXFGA3HBrRLTHzqzsfUlUAbV+SBm/FSFkuWsy4QWAuJCbnCnv
c3ClFHXqwaIq9UWvO5FR5kD4gK9LZOUY4B7tLTQmpJScFSiPZrIBa1cQ5uWl
-----END CERTIFICATE-----
- The collection of one or more root CA certificates should be concatenated
together into a single file.
- Copy this root CA certificate file as "/var/tmp/mgsft_rollout_cert" before
installing the Managed Devices client.
- During installation of the client, the "/var/tmp/mgsft_rollout_cert" file
will be copied to "/var/opt/managesoft/etc/ssl/cert.pem".
- If the Managed Devices client is already installed, then the certificate
file may be directly copied to "/var/opt/managesoft/etc/ssl/cert.pem".
- Ensure that all CA certificates within a certificate chain up to the
root CA include a reference to a downloadable Certificate Revocation
List (CRL). The reference to the CRL must be described using the X509v3
extensions "X509v3 CRL Distribution Points". The CRL must be downloadable
using the HTTP protocol and must be in DER format (a binary file).
Additional configuration options:
CheckServerCertificate - Check the server certificate's existence, name,
validity period, and issuance by a trusted certificate authority (CA).
This can be configured using "MGSFT_HTTPS_CHECKSERVERCERTIFICATE" with
"true" or "false" in the mgsft_rollout_response file.
This setting lives under the [ManageSoft\Common] section as
CheckServerCertificate in "/var/opt/managesoft/etc/config.ini".
CheckCertificateRevocation - Additionally check that the server certificate
has not been revoked. Already supported on Windows.
This can be configured using "MGSFT_HTTPS_CHECKCERTIFICATEREVOCATION"
with "true" or "false" in the mgsft_rollout_response file.
This setting lives under the [ManageSoft\Common] section as
CheckCertificateRevocation in "/var/opt/managesoft/etc/config.ini".
Additional Information
Additional information on the configuring SSL certificates for Windows and other Managed Devices can be found in the Preferences for Managed Devices Guide.
Related Articles
How do I manually install and pre-configure the non-windows agent (Linux/Unix/OSX/AIX/Solaris) 9Number of Views How do I configure managed devices to be tenant specific using an off-line inventory beacon? 7Number of Views Secure your estate with HTTPS and TLS 135Number of Views How to Configure a Major Upgrade 6Number of Views How to Configure the Snow Adobe Creative Cloud Connector 81Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago