The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Authentication of access to the Manager using CAC/PIV

Prev Next

Note

This section is not applicable for Common Criteria evaluated configuration.

Common Access Card (CAC) and Personal Identification Verification (PIV) are smart cards that are used for general identification as well as authentication of user access to secure networks. CAC/PIV holds a unique digital certificate and user information, such as photograph, personal identification number (PIN), and signature, to identify each user. Trellix IPS provides an option for authentication of users to log onto the Manager based on their smart card verification.

Authentication to the Manager using CAC/PIV requires a smart card reader connected to the Manager client workstation. The administrator inserts the CAC/PIV into the smart card reader and opens the Manager UI through the web browser. The Manager sends an SSL certificate to the client and requests the user’s certificate from the browser. The browser validates if the Manager's certificate is signed by a trusted Certificate Authority. The browser then selects the user’s certificate by prompting the user if required. The browser retrieves the selected certificate from the smart card which triggers the CAC/PIV interface software (called middleware) to request the user PIN associated with the smart card. The user must correctly enter the PIN to unlock the smart card.

The Manager validates the following attributes of the user’s certificate:

  • If the certificate is signed by a trusted Certificate Authority (CA)

  • If the certificate is valid and has not been revoked

  • When the certificate was last validated

The Manager extracts the common name from the user’s certificate and checks for a matching administrator account in the Manager with that common name. If the match is successful, a secure session is established and the user is logged into the Manager.

To validate the user’s certificate, the trust chain is validated by two CA certificates. The first validation is that the client's certificate is signed by the intermediary CA. Then the intermediary CA certificate is validated by verifying if it was signed by the root CA which is trusted. The root CA is a self-signed CA that is used to sign the intermediary CA certificates.

At a high level, authenticating user access to the Manager through CAC/PIV can be brought about by a 5-step process:

  • Obtain the CA certificates

  • Import the CA certificates

  • Set up CAC users in the Manager

  • Enable the CAC authentication

  • Log on to the Manager using the CAC/PIV authentication