You can import the public certificate and private key that the Evidence Collector module uses to authenticate with Helix by using the Network Security appliance Web UI or CLI:
Important
The public certificate and private key are downloaded and installed automatically when Helix Enterprise mode is enabled on the Network Security appliance. If Helix Enterprise mode is enabled, do not perform these manual procedures without guidance from Trellix Technical Support.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
Verify that the Evidence Collector module is disabled. Use the
show tapsender statuscommand.Download the bootstrap certificate bundle to your local desktop from the Operational Dashboard in the Helix Web UI. For details about how to download the certificate bundle, refer to Communications Broker Installation Guide 1.1.
An archive management program for files extracted to the desktop.