The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Enable the CAC authentication

Prev Next

The CAC authentication feature is disabled by default. It is mandatory to set up the CAC user accounts and import the CAC certificates to the Manager, before enabling it.

To enable CAC, do the following:

Steps:

  1. Log in to the Manager GUI.

  2. Go to, Manager → <Admin Domain Name> → Setup → GUI Access → CAC Authentication.

    The CAC Authentication page opens.

    GUID-EBFFBCD8-7827-4A0B-92D7-0FA7CAB17618-low.png
  3. In the Settings tab, configure the CAC Authentication as needed.

    GUID-53492448-05AC-4BCE-A191-B5BA21DA0641-low.png

    The table below describes the fields available for configuration:

    Field

    Description

    CAC Support Enabled

    Select the checkbox to enable CAC Authentication. By default, the CAC Authentication is disabled.

    Raise Fault for Expiring Certificates

    Select the checkbox to configure the Manager to generate faults when a trusted certificate is about to expire.

    Expiration Threshold (days)

    Number of days for the trusted certificate expiration when a fault is generated in the Manager.

    Note

    The Expiration Threshold (days) can be within the range of 30 to 60 days only.

    Note

    The Expiration Threshold (days) can be configured only when the Raise Fault for Expiring Certificate option is enabled.

    Enable OCSP Support

    Select the checkbox to enable OCSP Support. By default, the OCSP Support is disabled.

    OCSP Options

    OCSP URL

    Select Default to use the OCSP URL defined in the trusted certificate or Custom to configure a unified OCSP URL for all trusted certificates in the Manager.

    Custom URL

    Specify the OCSP URL for authenticating the trusted certificates.

    Note

    The Custom URL field is available only when you have the OCSP URL option set to Custom.

    Require OCSP Re-Check

    Select Yes to verify the authenticity of the trusted certificate after a definite interval.

    Re-Check Interval (minutes)

    Specify the duratin in minutes after which the authenticity of the trusted certificate is rechecked.

    Note

    The Re-Check Interval (minutes) can be within the range of 30 to 1440 minutes only.

    Note

    The Re-Check Interval (minutes) can be configured only when the Require OCSP Re-Check option is enabled.

  4. Click Save.

  5. Log in to the Manager shell.

  6. Stop the Manager service using the manager stop command.

  7. Restart the Manager service using the manager start command.