The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Regenerating certificates

Prev Next

You can reset the Trellix Endpoint Security (HX) xAgent and Endpoint Security (HX) series communications server public key infrastructure (PKI), including a certificate authorities (CA).

Caution

Using this command orphans any existing agents connected to the Endpoint Security (HX) PKI.

Regenerating certificates automatically detaches any DMZ server from the Endpoint Security (HX) server. You need to reattach them after the certificates are regenerated. See the Endpoint Security (HX) Server Deployment Guide.

To regenerate the PKI and certficate authorities:
  1. Enable CLI configuration mode.

    hostname > enablehostname # configure terminal
  2. Regenerate the PKI and certificate authorities:

    hostname (config) # hx pki regenerate
  3. Save your changes:

    hostname (config) # write memory