DLP MPKI Service Update 2025
search cancel

DLP MPKI Service Update 2025

book

Article ID: 401550

calendar_today

Updated On:

Products

Data Loss Prevention

Issue/Introduction

MPKI Service Update


Broadcom uses an MPKI service to issue and validate Data Loss Prevention (DLP) Cloud bundles. This service will be deprecated between at the end of December 2025, and replaced with a newer version. See this product advisory.

 

Resolution

Action Required:


Customers using cloud detection servers AND the following DLP versions must apply the June 11, 2025 hotfix (or a later version) to their Enforce Server to maintain uninterrupted service:
16.0 MP2
16.0 RU1 MP1
16.0 RU2

Note: Versions 16.1 and later are not affected. Customers on 15.8 will need to upgrade to a supported version.

 

Impact of Not Applying the Hotfix:


Failure to apply the hotfix will result in the Enforce Server being unable to:

  • Apply new Cloud bundles
  • Renew existing Cloud certificates. This will result in disconnected cloud servers.

If a bundle is applied or a certificate is renewed before January 1st 2026, Cloud server connections will continue functioning for one year from that point. After that, the June 2025 hotfix (or later) must be installed to maintain connectivity.

 

Important Note:


Enforce Servers without the hotfix will continue to connect to cloud detection servers using existing cloud certificates—but only until those certificates expire and require renewal.

 

Recommendation:


Customers on any 16.0.x version using cloud services should upgrade to 16.1 (or later) or:

  1. Upgrade to the latest available version of their existing install (16.0 MP2 / 16.0 RU1 MP1 / 16.0 RU2)
  2. Apply the June 11, 2025 hotfix or any newer hotfix available at that time. 

 

FAQ:

Q: How do I see when my certificate expires?

A: Navigate to System > Settings > General. You can see the Expires on date under Cloud Certificate.