BigFix PlugIn and MDM SSL certificates and keys
SSL certificates and keys are required to authenticate the BigFix MDM PlugIns to the MDM Server.
These certificates and keys must be generated through the BESAdmin
command. The generated SSL certificates and keys are stored in the directory that you
specify in the BESAdmin command.
Note: You must have a reachable
DNS host name to run the commands in the BESAdmin tool to generate
certificates.
To generate SSL certificates on a Windows BigFix root server,
run this
command:
BESAdmin.exe /generateplugincertificates /certificatespath:<path-to-store-certs> [/commonname:<CN-for-server-and-client-cert>]
To
generate SSL certificates on a Linux BigFix root server, run this
command:
BESAdmin.sh -generateplugincertificates -certificatespath=<path-to-store-certs> [-commonname:<CN-for-server-and-client-cert>
Note:
- For commonname, use the FQDN name of the MDM Server.
- These commands work only if path-to-store-certs directory exists.
The following SSL certificates are generated in the folder that you created. You
have to use these SSL certificates and keys when you install the MDM Plugin and
MDM Server.
- ca.cert.pem
- client.cert.pem
- client.key
- server.cert
- server.key
- BigFix MDM server TLS certificate and key
- The BigFix MDM server requires a CA-signed TLS certificate to protect the communications from the endpoint to the BigFix MDM server. The SSL certificate is deployed through the MDM Server installation in the WebUI.