The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Installation of the Agent for DH ciphers

Prev Next

Before you enable the inbound SSL decryption for DH ciphers, install the Agent on the web servers to be protected. You can download the Trellix SSL Agent from the Download Server using your Grant Number. The SSL Agent download file is available under Utilities & Connectors in the Download Server. The Trellix SSL Agent is a tgz file that is downloaded as a trellixsslagent.tgz file to be installed on the web servers. The web server to be protected should have the Agent installed on it.

Note

Agent based method is not supported for AWS, Azure and GCP cloud platforms.

Note

The Trellix SSL Agent can be installed on Linux based web servers only across multiple distributions like RHEL, Ubuntu, Fedora, etc.

To install the Agent on the web server, perform the following steps:

  1. Untar the agent tarball trellixsslagent.tgz.

    #tar -zxvf trellixsslagent.tgz

  2. Untar produces a directory that has similar content as the following:

    [root@Server_FC12_174_136 ~]# ls -al /root/trellixsslagent

    total 132

    drwxr-xr-x 2 root root 4096 Oct 11 16:02 .

    drwxr-xr-x 3 root root 4096 Oct 11 16:02 ..

    -rw-r--r-- 1 1001 1001 87 Oct 11 09:59 install.sh

    -rw-r--r-- 1 1001 1001 27436 Oct 11 09:59 trellixsslagent-1.0.1-0.i686.deb

    -rw-r--r-- 1 1001 1001 29218 Oct 11 09:59 trellixsslagent-1.0.1-0.i686.rpm

    -rw-r--r-- 1 1001 1001 27778 Oct 11 09:59 trellixsslagent-1.0.1-0.x86_64.deb

    -rw-r--r-- 1 1001 1001 29556 Oct 11 09:59 trellixsslagent-1.0.1-0.x86_64.rpm

    [root@Server_FC12_174_136 ~]#

  3. Install the agent by executing the following shell script:

    chmod +x install.sh

    /install.sh

    Verify the installation by looking for the below files:

    ls -al /etc/trellixsslagent/agent.conf

    ls -al /usr/lib/libtrellixsslagent.so

  4. Edit the Trellix SSL Agent configuration file /etc/trellixsslagent/agent.conf to set the correct parameters primarily the Sensor IP address and SSL library name (parameters are described in the configuration file).

    # IP address of the sensor(v4/v6) in case of

    # a standalone deployment

    # In case of HA/Stack setup(Active/standby or

    # Active/Active), comma-separated IP address's

    # of primary and secondary/stack nodes

    # for e.g: 10.1.1.190,10.1.1.191

    #

    SENSORIP=x.x.x.x

    #

    # libopenssl library name used by the

    # Apache or nginx

    # on some platforms, there are multiple

    # versions of openssl installed

    # and this ensures that correct openssl

    # library is intercepted

    #

    # default: libssl.so

    #

    LIBSSLNAME=libssl.so.10

  5. For Apache/HTTPD, edit the script is located at /usr/lib/systemd/system/httpd.service to add a new Environment variable under the section "[Service]" as shown below:

    Environment="LD_PRELOAD=/usr/lib64/libtrellixsslagent.so"

  6. For Apache Webserver:

    Edit the Apache Startup script to load the Trellix SSL Agent as shown as follows:

    /usr/sbin/apachectl (On some installations the path may be different. In such cases, you have do a find)

    Original script

    ---------------

    case $ARGV in

    start|stop|restart|graceful|graceful-stop)

    $HTTPD -k $ARGV

    ERROR=$?

    ;;

    Modified script

    ---------------

    case $ARGV in

    start)

    LD_PRELOAD=/usr/lib/libtrellixsslagent.so $HTTPD -k $ARGV

    #$HTTPD -k $ARGV

    ERROR=$?

    ;;

    stop|restart|graceful|graceful-stop)

    $HTTPD -k $ARGV

    ERROR=$?

    ;;

    Restart the Apache

    #apachectl stop; apachectl start

  7. For Nginx Webserver:

    Nginx is usually started by the command line /usr/bin/nginx or /usr/sbin/nginx.

    Edit the startup command line and use

    <bash>#LD_PRELOAD=/usr/lib/libtrellixsslagent.so /usr/bin/nginx

    or

    <bash>#LD_PRELOAD=/usr/lib/libtrellixsslagent.so /usr/sbin/nginx

    Optional steps:

    On most of the servers, syslog is configured to log till "INFO" level only. If LOG_DEBUG messages are to be logged, which is what the Agent uses to dump more information, syslog configuration needs modification.

    Edit the file /etc/rsyslog.conf and search for the line similar to the line below:

    *.info;mail.none;news.none;authpriv.none;cron.none /var/log/messages

    change it to

    *.debug;mail.none;news.none;authpriv.none;cron.none /var/log/messages

  8. For CentOS server:

    1. Install semanage utility using the below command:

      yum install /usr/sbin/semanage

    2. Check the ports assigned to Apache/HTTPD process:

      semanage port -l | grep -w http_port_t

      Example:

      [root@localhost Apurva]#  semanage port -l | grep -w http_port_t
      http_port_t tcp 80, 81, 443, 488, 8008, 8009, 8443, 9000
    3. Add port 8501 to the list.

      Note

      8501 is the listening port in the Sensor. The apache process in the CentOS server needs to initiate a connection to port 8501 of the Sensor.

      semanage port -a -t http_port_t -p tcp 8501

    4. Verify that port 8501 has been added to the list.

      Example:

      [root@localhost Apurva]#  semanage port -l | grep -w http_port_t
      http_port_t tcp 8501, 80, 81, 443, 488, 8008, 8009, 8443, 9000
    5. Reload the system daemon and restart the Apache/HTTPD service.

      Reload the system daemon using the command root#systemctl daemon-reload.

      Restart the Apache/HTTPD service using the command root#service httpd restart OR apachectl restart.