The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure HTTPS for DLP Server

Prev Next

DLP Server uses HTTPS as a secure communications channel with other Trellix servers. After installing DLP Server, configure the server to enable HTTPS.

Obtain a certificate file from the certificate authority. You can use the certificate request tool (Server Certificates → Actions → Create Certificate Request in IIS to obtain the certificate.

Trellix DLP Server software employs Microsoft Internet Information Services (IIS) as a web server, using HTTPS as a secure communications channel. HTTPS uses Secure Sockets Layer (SSL) to exchange information between the server and clients. To enable SSL/HTTPS in IIS you must configure the server with an SSL certificate file obtained from a certification authority.

  1. Obtain a certificate file.

    1. In IIS, go to Server Certificates → Actions → Create Certificate Request.

    2. Fill in the required fields on the first page and click Next.

    3. Review the second page. In most cases, you can accept the defaults. Click Next, then Finish.

    4. Send your request to the certificate authority to order your certificate.

  2. Install the certificate file.

    1. In IIS, go to Server Certificates → Actions → Complete Certificate Request.

    2. Enter the name of the file you received from the certificate authority.

    3. In the Friendly name field, enter the name you want to appear in the IIS certificates list.

    4. Select Personal for the certificate store value, then click OK.

      The certificate appears in the IIS certificates list.

  3. Create a binding.

    This step is required to make the web site available by HTTPS.

    1. In the Connections (left) panel in IIS, select DlpServer.

    2. Select Actions → Bindings.

    3. Select https, then click Edit.

    4. Select your certificate (by Friendly name) from the SSL certificate drop-down list. Click OK.

We recommend configuring IIS to accept connections only from a list of specified Trellix DLP Discover, Trellix DLP Network Prevent, Trellix DLP Network Monitor, and other Trellix servers that need access to the DLP Servers. For information on restricting IIS to specific IPs, see Microsoft's IP Security documentation.