The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing the SSL Certificates and the Private Keys for the Communications Broker Sender Using the CLI

Prev Next

Use the CLI commands to import the public certificate and private key for the SSL server and the root certificate authority (CA) certificate to establish a secure SSL connection for the Communications Broker Sender (Comm Broker) input module on the Network Security appliance.

Important

Mutual authentication between the Network Security appliance and the third-party log forwarding server is required. The third-party server must provide a client certificate and the client certificate must be trusted by the Network Security appliance. See your third-party log forwarding server documentation for steps to set up a client TLS certificate.

Important

After you apply the certificates to establish a secure SSL connection, use the commbroker enable command to enable the Comm Broker.

To import the public certificate and private key for the SSL server:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Import the public certificate from the bootstrap.crt file that you already downloaded.

    hostname (config) # crypto certificate name <certificateName>public-cert pem"<pemString>" [comment"<comment>"]

    where:

    • <certificateName> is a name of your choice that uniquely identifies the certificate for the SSL server.

    • <pemString> is the public certificate PEM string for the SSL server. Copy the certificate content from the bootstrap.crt file. Paste the certificate content of the PEM string within the quotes.

    • <comment> is the text for the comment.

  3. Import the private key PEM string from the bootstrap.pem file that you already downloaded.

    hostname (config) # crypto certificate name <certificateName> private-key pem"<pemString>"

    where <pemString> is the private key PEM string for the SSL server. Copy the private key content from the bootstrap.pem file. Paste the private key content of the PEM string within the quotes.

  4. Apply the uploaded certificate for the SSL server to the Comm Broker.

    hostname (config) # commbroker ssl server certificate name <certificateName>

    where <certificateName> is the name that you already configured to uniquely identify the certificate for the Comm Broker input module.

  5. Verify that the public certificate for the SSL server has been imported.

    hostname (config) # show commbroker ssl certificate
    Commbroker ssl server certificate: cb-ssl-certs
    Commbroker ssl rootca certificate: rootCA
  6. Save your changes.

    hostname (config) # write memory
To import the root CA certificate for the Comm Broker:
  1. Go to CLI configuration mode.

    hostname > enable
    hostname # configure terminal
  2. Import the root private key PEM string from the rootCA.pem file that you already downloaded for your CA.

    hostname (config) # crypto certificate name <certificateName> private-key pem"<pemString>"

    where <pemString> is the root private key PEM string for the root CA certificate. Copy the private key content from the rootCA.pem file. Paste the private key content of the PEM string within the quotes.

  3. Apply the uploaded root CA certificate to the Comm Broker input module.

    hostname (config) # commbroker ssl rootca certificate name <certificateName>

    where <certificateName> is the name that you already configured to uniquely identify the root CA certificate for the Comm Broker input module.

  4. Verify that the root CA certificate has been imported.

    hostname (config) # show commbroker ssl certificate
    Commbroker ssl server certificate: cb-ssl-certs
    Commbroker ssl rootca certificate: rootCA
  5. Save your changes.

    hostname (config) # write memory