The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing a certificate and a private Key for the Evidence Collector module using the CLI

Prev Next

Important

The public certificate and private key are downloaded and installed automatically when Helix Enterprise mode is enabled on the Network Security appliance. If Helix Enterprise mode is enabled, do not perform this manual procedure without guidance from Trellix Technical Support.

Use the CLI commands to import the public certificate and private key that the Evidence Collector module uses to authenticate with Helix Enterprise.

Important

After the certificate is applied, use the tapsender enable command to enable the Evidence Collector module.

To import the public certificate and private key for the Evidence Collector module:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Import the public certificate from the bootstrap.crt file that you already downloaded.

    hostname (config) # crypto certificate name <certificateName>public-cert pem"<pemString>" [comment"<comment>"]

    where:

    • <certificateName> is a name of your choice that uniquely identifies the certificate.

    • <pemString> is the public certificate PEM string. Copy the certificate content from the bootstrap.crt file. Paste the certificate content of the PEM string within the quotes.

    • <comment> is the text for the comment.

  3. Import the private key PEM string from the bootstrap.pem file that you already downloaded.

    hostname (config) # crypto certificate name <certificateName> private-key pem "<pemString>"

    where <pemString> is the private key PEM string. Copy the private key content from the bootstrap.pem file. Paste the private key content of the PEM string within the quotes.

  4. Apply the uploaded certificate to the Evidence Collector module.

    hostname (config) # tapsender certificate name <certificateName>

    where <certificateName> is the name that you already configured to uniquely identify the certificate for the Evidence Collector module.

  5. Verify that the public certificate has been imported.

    hostname (config) # show tapsender certificate
    Tapsender certificate: hexkhiorg
  6. Save your changes.

    hostname (config) # write memory