The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Regenerating certificates

Prev Next

You can reset the Trellix Endpoint Security (HX) Agent and Endpoint Security (HX) Server public key infrastructure (PKI), including a certificate authorities (CA).

Caution

Using this command orphans any existing agents connected to the Endpoint Security (HX) PKI.

Regenerating certificates automatically detaches any DMZ server from the Endpoint Security (HX) server. You need to reattach them after the certificates are regenerated. See the Endpoint Security (HX) Server Deployment Guide.

To regenerate the PKI and certificate authorities:
  1. Enable CLI configuration mode.

    hostname > enable
    hostname # configure terminal
                      
  2. Regenerate the PKI and certificate authorities:

    hostname (config) # hx pki regenerate
                      
  3. Save your changes:

    hostname (config) # write memory