Before you enable the inbound SSL decryption for DH ciphers, install the Agent on the web servers to be protected. You can download the Trellix SSL Agent from the Download Server using your Grant Number. The SSL Agent download file is available under Utilities & Connectors in the Download Server. The Trellix SSL Agent is a tgz file that is downloaded as a trellixsslagent.tgz file to be installed on the web servers. The web server to be protected should have the Agent installed on it.
Note
Agent based method is not supported for AWS, Azure, and OCI cloud platforms.
Note
The Trellix SSL Agent can be installed on Linux based web servers only across multiple distributions like RHEL, Ubuntu, Fedora, etc.
To install the Agent on the web server, perform the following steps:
Task
-
Untar the agent tarball trellixsslagent.tgz.
#tar -zxvf trellixsslagent.tgz
-
Untar produces a directory that has similar content as the following:
[root@Server_FC12_174_136 ~]# ls -al /root/trellixsslagent
total 132
drwxr-xr-x 2 root root 4096 Oct 11 16:02 .
drwxr-xr-x 3 root root 4096 Oct 11 16:02 ..
-rw-r--r-- 1 1001 1001 87 Oct 11 09:59 install.sh
-rw-r--r-- 1 1001 1001 27436 Oct 11 09:59 trellixsslagent-1.0.1-0.i686.deb
-rw-r--r-- 1 1001 1001 29218 Oct 11 09:59 trellixsslagent-1.0.1-0.i686.rpm
-rw-r--r-- 1 1001 1001 27778 Oct 11 09:59 trellixsslagent-1.0.1-0.x86_64.deb
-rw-r--r-- 1 1001 1001 29556 Oct 11 09:59 trellixsslagent-1.0.1-0.x86_64.rpm
[root@Server_FC12_174_136 ~]#
-
Install the agent by executing the following shell script:
chmod +x install.sh
/install.sh
Verify the installation by looking for the below files:
ls -al /etc/trellixsslagent/agent.conf
ls -al /usr/lib/libtrellixsslagent.so
-
Edit the
Trellix SSL Agent configuration file
/etc/trellixsslagent/agent.conf to set the correct parameters primarily the Sensor IP address and SSL library name (parameters are described in the configuration file).
# IP address of the sensor(v4/v6) in case of
# a standalone deployment
# In case of HA/Stack setup(Active/standby or
# Active/Active), comma-separated IP address's
# of primary and secondary/stack nodes
# for e.g: 10.1.1.190,10.1.1.191
#
SENSORIP=x.x.x.x
#
# libopenssl library name used by the
# Apache or nginx
# on some platforms, there are multiple
# versions of openssl installed
# and this ensures that correct openssl
# library is intercepted
#
# default: libssl.so
#
LIBSSLNAME=libssl.so.10
-
For Apache/HTTPD, edit the script is located at /usr/lib/systemd/system/httpd.service to add a new
Environment variable under the section
"[Service]" as shown below:
Environment="LD_PRELOAD=/usr/lib64/libtrellixsslagent.so"
-
For Apache Webserver:
Edit the Apache Startup script to load the Trellix SSL Agent as shown as follows:
/usr/sbin/apachectl (On some installations the path may be different. In such cases, you have do a find)
Original script
---------------
case $ARGV in
start|stop|restart|graceful|graceful-stop)
$HTTPD -k $ARGV
ERROR=$?
;;
Modified script
---------------
case $ARGV in
start)
LD_PRELOAD=/usr/lib/libtrellixsslagent.so $HTTPD -k $ARGV
#$HTTPD -k $ARGV
ERROR=$?
;;
stop|restart|graceful|graceful-stop)
$HTTPD -k $ARGV
ERROR=$?
;;
Restart the Apache
#apachectl stop; apachectl start
-
For Nginx Webserver:
Nginx is usually started by the command line /usr/bin/nginx or /usr/sbin/nginx.
Edit the startup command line and use
<bash>#LD_PRELOAD=/usr/lib/libtrellixsslagent.so /usr/bin/nginx
or
<bash>#LD_PRELOAD=/usr/lib/libtrellixsslagent.so /usr/sbin/nginx
Optional steps:
On most of the servers, syslog is configured to log till "INFO" level only. If LOG_DEBUG messages are to be logged, which is what the Agent uses to dump more information, syslog configuration needs modification.
Edit the file /etc/rsyslog.conf and search for the line similar to the line below:
*.info;mail.none;news.none;authpriv.none;cron.none /var/log/messages
change it to
*.debug;mail.none;news.none;authpriv.none;cron.none /var/log/messages
-
For CentOS server:
-
Install
semanage utility using the below command:
yum install /usr/sbin/semanage
-
Check the ports assigned to Apache/HTTPD process:
semanage port -l | grep -w http_port_tExample:
[root@localhost Apurva]# semanage port -l | grep -w http_port_t http_port_t tcp 80, 81, 443, 488, 8008, 8009, 8443, 9000 -
Add port
8501 to the list.
Note
8501 is the listening port in the Sensor. The apache process in the CentOS server needs to initiate a connection to port 8501 of the Sensor.
semanage port -a -t http_port_t -p tcp 8501 -
Verify that port
8501 has been added to the list.
Example:
[root@localhost Apurva]# semanage port -l | grep -w http_port_t http_port_t tcp 8501, 80, 81, 443, 488, 8008, 8009, 8443, 9000 -
Reload the system daemon and restart the Apache/HTTPD service.
Reload the system daemon using the command root#systemctl daemon-reload.Restart the Apache/HTTPD service using the command root#service httpd restart OR apachectl restart.
-
Install
semanage utility using the below command: