The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing a certificate and a private Key for the Evidence Collector module

Prev Next

You can import the public certificate and private key that the Evidence Collector module uses to authenticate with Helix by using the Network Security appliance Web UI or CLI:

Important

The public certificate and private key are downloaded and installed automatically when Helix Enterprise mode is enabled on the Network Security appliance. If Helix Enterprise mode is enabled, do not perform these manual procedures without guidance from Trellix Technical Support.

Prerequisites

  • Administrator or Operator access to the Network Security appliance

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud

  • An active subscription to Helix

  • Verify that the Evidence Collector module is disabled. Use the show tapsender status command.

  • Download the bootstrap certificate bundle to your local desktop from the Operational Dashboard in the Helix Web UI. For details about how to download the certificate bundle, refer to Communications Broker Installation Guide 1.1.

  • An archive management program for files extracted to the desktop.