The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Considerations for CA-signed certificate chain

Prev Next

The CA-signed certificate chain for the Manager and the Sensor is considered valid if the following conditions are met:

  • The CSR should not be modified after exporting from the Manager. This will cause the certificate validation in the Manager to fail.

  • The certificate must be X.509v3 version.

  • The CA-signed certificate chain should comply with the following requirements:

    • Should be issued from a trusted Certificate Authority

    • Should be in .pem format

    • Must contain valid serial numbers and valid issuer domain name

  • The number of intermediate CA-certificates in the certificate chain should be between 0 and 4.

  • The certificate chain should be in correct order. The chain should begin with the identity certificate (also known as leaf certificate) followed by intermediate CA-certificate 1, intermediate CA-certificate 2, ... intermediate CA-certificate N and end with the root CA-certificate.

  • The identity certificate must be signed by the intermediate CA. The intermediate certificate must be signed by the root CA.

  • The Basic Constraint CA flag must be set to True in case of root and intermediate certificates. For identity certificate, the flag must be set to False.

  • The certificate must comply with the following parameters:

    • ExtendedKeyUsage: TLS WebServerAuthentication and TLS WebClientAuthentication

    • KeyUSage: Must not be set to Critical.

  • Ensure that the validity period for the certificate specifies a valid date range.

  • OCSP requests and responses use CertID.issuerNameHash and CertID.issuerKeyHash parameters to validate the revocation status of CA certificates.

    Note

    In a Common Criteria (CC) evaluated configuration, revocation using OCSP is not claimed for Sensor - Manager channel.

    Currently, the Manager supports SHA-1 hashing algorithm for the two parameters which needs to be managed in OCSP server configuration.