Renewing the Symantec Endpoint Encryption Management Server TLS certificate (SEE)
search cancel

Renewing the Symantec Endpoint Encryption Management Server TLS certificate (SEE)

book

Article ID: 176302

calendar_today

Updated On:

Products

Endpoint Encryption Desktop Email Encryption Drive Encryption Encryption Management Server File Share Encryption Gateway Email Encryption PGP Command Line PGP Key Management Server PGP Key Mgmt Client Access and CLI API PGP SDK PGP Encryption Suite

Issue/Introduction

Before the TLS certificate for Endpoint Encryption Management Server expires, you will need to replace it with a new certificate or Endpoint Encryption clients will fail to connect.

Usually, you will not need to build and roll out a new Endpoint Encryption client.

Resolution

Note: If the Root Certificate Authority is expired, or you changed the Root Certificate Authority (CA Certificate), in 12.0.1 and above, simply log in to the Web Console, go to Settings -> CA Certificate -> Update the CA Certificate automatically and enable this setting and save the changes.  Once this is done, then go to the SEEMS Configuration Manager, and update the "CA Certificate" with the new Root Certificate Authority and the Server Certificate, and save.  Once this is done, the next time the SEE Client checks in with the SEE Management Server, the new certificates will be presented.  If you are on an older version than this, update to receive this new functionality. 

If the root certificate of the new SEE Management Server certificate is the same as the old one, the Endpoint Encryption clients will continue to trust the Endpoint Encryption Management Server certificate.

If the new SEE Management Server certificate has a different root certificate, the Endpoint Encryption clients will trust the SEE  Management Server certificate provided and that the SEE Management Server's root certificate is in the Trusted Root Certification Authorities container of the Local Computer certificate store of the clients.

Once you have obtained a new server certificate for the SEE  Management Server, please do the following:

1. The new server certificate must contain the Server Authentication attribute within the Enhanced Key Usage section. See this article for more details, 172147 - Endpoint Encryption Server Configuration Manager cannot browse to the Server Certificate . If it does not, the certificate cannot be used. All server certificates issued by well-known Certificate Authorities will contain the Server Authentication attribute but this is not necessarily the case with certificates issued by internal Certificate Authorities.

2. The new server certificate must have the same Common Name (CN) as the old certificate. For example, see.example.com.

3. Ensure that the Endpoint Encryption clients trust the new certificate's root certificate. In order to trust the root certificate, it needs to be in the Trusted Root Certification Authorities container of the Local Computer Windows certificate store. Note that placing the root certificate in the Current User certificate store is not sufficient. If the new server certificate was issued by a well known Certificate Authority then it is likely that the root certificate will already be in the correct location within the Windows certificate store, so long as the latest Windows Updates have been installed. The same is likely to be true if the new server certificate was issued by your internal Certificate Authority. This is because the root certificate will usually have been rolled out to all clients in the Windows domain using group policy. However, it is essential to check that this requirement is met before replacing the server certificate.

4. Install the private certificate on the SEE Management Server. Import the *.p12 or *.pfx file into the Local Computer certificate store and accept the default location. Do not import it into the Current User certificate store.

5. Export either the public server certificate or the issuing root certificate to a DER format file. DER is a binary format and is the default format used by Windows to export public certificates.

6. In the SEE Management Server Configuration Manager, use the Server Certificate button to choose the appropriate server certificate from a list of the server certificates that are available in the Windows certificate store.

7. In the SEE Management Server Configuration Manager, use the CA Certificate button to browse to the DER format file containing either the root certificate or the server certificate. If you browse to the server certificate, The Configuration Manager will automatically find the associated root certificate.

8. Configuration Manager will display the Thumbprint of the Server and CA certificates. Check these against the public certificates by opening both public certificates in Windows and checking the Thumbprint section in the Details tab.

9. Once you have saved the new settings in Configuration Manager, the Endpoint Encryption clients will continue to be able to connect to the SEE Management Server.

Additional Information

178609 - Creating an SSL certificate to secure SEE Client Communication with the Symantec Endpoint Encryption Management Server (SEE)

214267 - Enable TLS/SSL for the Database on Symantec Endpoint Encryption Configuration Manager (SEE)

176302 - Renewing the Symantec Endpoint Encryption Management Server TLS certificate (SEE)

155127 - Symantec Endpoint Encryption Client communication and SEE Client Creation troubleshooting steps

155218 - Generate a new self-signed Organization Certificate for PGP Encryption Server for SMIME Email Encryption (PGP)

180416 - Installing an SSL Certificate for PGP Encryption Server (Symantec Encryption Management Server)

257339 - Creating and Assigning a Subordinate/Intermediate Certificate for SMIME/Certificate Signing with PGP Encryption Management Server (PGP)

180143 - Working with Trusted Keys and Certificates on the PGP Encryption Server (Symantec Encryption Management Server)