The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import the custom certificates into the Manager keystore

Prev Next

You can import the custom certificates into the Manager keystore. To do so, perform the following steps.

Task

  1. On the Manager create a new folder named customcerts at <Manager install directory>\config\fscerts\customcerts
  2. Copy the ThirdPartyAPI-SSL.zip from Vulnerability Manager server to a temporary folder on the Manager server and extract the contents to the customcerts folder you just created.
  3. On the Manager server, select Start → Run, type cmd, and then click OK. Navigate to <Manager install directory>\bin
  4. At the command prompt, for the parent and each child domain created on the Manager, type the following commands using the following parameters:
    FScertimport <MVM version #> <”MainDomainName\ChildDomainName”>
    For example, if your main domain in the Manager is “AmazingDeals”, you have created child domains named “EastCoast”, “MidWest”, and “WestCoast” under that domain, and you are integrating with Vulnerability manager 7.0, your certificate install commands would be as follows:
    • FScertimport 7.0 ”AmazingDeals”
    • FScertimport 7.0 ”AmazingDeals\EastCoast”
    • FScertimport 7.0 ”AmazingDeals\MidWest”
    • FScertimport 7.0 ”AmazingDeals\WestCoast”
  5. Each time you run the Vulnerability Manager Certificate importer, you will be asked for the Import password. Enter that passphrase at the Import Password prompt.
    This is the passphrase that you captured when the Certificate Management Tool was run on Vulnerability Manager server.
  6. Enter Y for the Trust this Certificate? [no] prompt.
  7. The custom certificates are now imported to the Manager.
  8. The FSCertImport.bat utility generates two keystore files (fs.keystore and fstrust.keystore) each time you run the utility. These files are placed in the customcerts folder in a hierarchy of \Version#\DomainName.
  9. Run an OnDemand scan from Threat Explorer for any IP to check if the client authentication works for the newly imported keystore files generated for Vulnerability Manager custom certificates.