The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Importing the SSL certificates and the private keys for the Communications Broker Sender using the Web UI

Prev Next

Use the SSL Certificate Configuration section of the Evidence Collector page to import the public certificate and private key for the SSL server and the root CA certificate to establish a secure Network SecuritySSL connection for the Communications Broker Sender (Comm Broker) on the appliance.

NX_CommbrokerSSLCertKey_scap.png

Important

Mutual authentication between the Network Security appliance and the third-party log forwarding server is required. The third-party server must provide a client certificate and the client certificate must be trusted by the Network Security appliance. See your third-party log forwarding server documentation for steps to set up a client TLS certificate.

To import the public certificate and private key for the SSL server:
  1. In the Web UI, choose Settings > Evidence Collector.

  2. Click Helix Integration.

  3. In the SSL Certificate Configuration area, click the Add Certificate link under the Server Certificate drop-down list. The Add Certificate/Key window opens.

    NX_CommbrokerSSLCert_Add_scap.png
  4. Select the public certificate for the SSL server:

    1. In the Certificate (PEM format) field, click Choose File.

    2. Navigate to the downloaded certificate bootstrap.pem file in your local desktop. If the file is hidden in the folder containing it, type the file name and extension.

  5. Select the private key for the SSL server:

    1. In the Private Key field, click Choose File.

    2. Navigate to the downloaded private key bootstrap file in your local desktop.

  6. In the Cert Name field, enter a unique certificate name (for example, web-cert-ssl_cb) of your choice.

  7. Click Commit to import the public certificate and private key for the SSL server.

  8. In the Server Certificate drop-down list, choose the certificate that you uploaded on the appliance.

  9. Click Update to apply the uploaded certificate to Comm Broker.

To import the root CA certificate for Comm Broker:
  1. In the Web UI, choose Settings > Evidence Collector.

  2. Click Helix Integration.

  3. In the SSL Certificate Configuration area, click the Add Certificate link under the Root CA Certificate drop-down list. The Add Certificate/Key window opens.

    NX_CommbrokerSSLrootCert_Add_scap.png
  4. Click Choose File.

  5. Navigate to the downloaded root CA certificate (for example, rootCA.pem) file in your local desktop. If the file is hidden in the folder containing it, type the file name and extension.

  6. Click Commit to import the root CA certificate.

  7. In the Root CA Certificate drop-down list, choose the certificate that you uploaded on the appliance.

  8. Click Update to apply the uploaded certificate to Comm Broker.