The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Regenerating the subordinate PKI

Prev Next

You can reset the Endpoint Security (HX) communications server subordinate public key infrastructure (PKI). Do this to resolve a date or configuration discrepancy that causes the subordinated PKI to become invalid.

Caution

Using this command invalidates any existing agent tasks.

Using this command detaches any DMZ server from the Endpoint Security (HX) server. You need to reattach them after running this command.

To regenerate the Endpoint Security (HX) subordinate PKI:
  1. Enable CLI configuration mode.

    hostname > enable
    hostname # configure terminal
                      
  2. Regenerate the subordinate PKI:

    hostname (config) # hx pki regenerate subordinate
                      
  3. Save your changes:

    hostname (config) # write memory