The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import SSL keys to the Manager for a Sensor

Prev Next

You can download Secure Socket Layer (SSL) keys to Manager for a single Sensor. Once imported to Manager, keys can be pushed to the Sensor via Configuration Update. Using provided SSL keys, a Sensor can decrypt SSL traffic for IPS inspection. Manager provides a passthru interface for you to import a set of public/private keys to the Sensor. Manager stores an escrow of the imported keys for Sensor recovery purpose. However, the Manager does not interpret the escrowed keys, nor does it attempt to recover the keys themselves in case a Sensor has lost its key encryption key. In order to protect the imported keys both in transit and in escrow, Manager uses the public key of the Sensor's public/private key pair.

Trellix IPS Manager supports PKCS12 keys with file suffixes ".pkcs12", ".p12", or ".pfx".

  1. Select Devices → <Admin Domain Name> → Global → IPS Device Settings → SSL Decryption.

    GUID-41AB6900-10A9-4D24-8827-D96BBBAC6FB5-low.png
  2. In the Inbound tab, select Internal Web Server Certificates tab.

  3. Click Import. The Import Internal Web Server Certificates dialog box opens.

    GUID-638384C2-19C6-4AB0-905E-79F37346F304-low.png
  4. Click Choose Files.

    Note

    You can import up to 200 certificate files at the same time as long as they use the same passphrase.

  5. Select the key PKCS12 File on your client system.

  6. Type the Passphrase.

    This is the phrase (export password) you used for encrypting your PKCS12 file.

  7. Click the Installed On tab and select the Sensors that you want to push the certificates to.

    GUID-DBEA7EFE-EA76-4E17-9ECA-4E15CACD9059-low.png

    Note

    If you do not select any Sensors, the certificates will be pushed to all the devices connected to the Manager.

  8. Click Import.

    A pop-up window opens detailing import status.

  9. You must do a configuration update to the Sensor for the changes to take effect.