Before you enable the inbound SSL decryption for DH ciphers, install the Agent on the web servers to be protected. You can download the Trellix SSL Agent from the Download Server using your Grant Number. The SSL Agent download file is available under Utilities & Connectors in the Download Server. The Trellix SSL Agent is a tgz file that is downloaded as a trellixsslagent.tgz file to be installed on the web servers. The web server to be protected should have the Agent installed on it.
Note
Agent based method is not supported for AWS, Azure and GCP cloud platforms.
Note
The Trellix SSL Agent can be installed on Linux based web servers only across multiple distributions like RHEL, Ubuntu, Fedora, etc.
To install the Agent on the web server, perform the following steps:
Untar the agent tarball trellixsslagent.tgz.
#tar -zxvf trellixsslagent.tgzUntar produces a directory that has similar content as the following:
[root@Server_FC12_174_136 ~]# ls -al /root/trellixsslagenttotal 132drwxr-xr-x 2 root root 4096 Oct 11 16:02 .drwxr-xr-x 3 root root 4096 Oct 11 16:02 ..-rw-r--r-- 1 1001 1001 87 Oct 11 09:59 install.sh-rw-r--r-- 1 1001 1001 27436 Oct 11 09:59 trellixsslagent-1.0.1-0.i686.deb-rw-r--r-- 1 1001 1001 29218 Oct 11 09:59 trellixsslagent-1.0.1-0.i686.rpm-rw-r--r-- 1 1001 1001 27778 Oct 11 09:59 trellixsslagent-1.0.1-0.x86_64.deb-rw-r--r-- 1 1001 1001 29556 Oct 11 09:59 trellixsslagent-1.0.1-0.x86_64.rpm[root@Server_FC12_174_136 ~]#Install the agent by executing the following shell script:
chmod +x install.sh/install.shVerify the installation by looking for the below files:
ls -al /etc/trellixsslagent/agent.confls -al /usr/lib/libtrellixsslagent.soEdit the Trellix SSL Agent configuration file
/etc/trellixsslagent/agent.confto set the correct parameters primarily the Sensor IP address and SSL library name (parameters are described in the configuration file).# IP address of the sensor(v4/v6) in case of# a standalone deployment# In case of HA/Stack setup(Active/standby or# Active/Active), comma-separated IP address's# of primary and secondary/stack nodes# for e.g: 10.1.1.190,10.1.1.191#SENSORIP=x.x.x.x## libopenssl library name used by the# Apache or nginx# on some platforms, there are multiple# versions of openssl installed# and this ensures that correct openssl# library is intercepted## default: libssl.so#LIBSSLNAME=libssl.so.10For Apache/HTTPD, edit the script is located at /usr/lib/systemd/system/httpd.service to add a new
Environmentvariable under the section"[Service]"as shown below:Environment="LD_PRELOAD=/usr/lib64/libtrellixsslagent.so"For Apache Webserver:
Edit the Apache Startup script to load the Trellix SSL Agent as shown as follows:
/usr/sbin/apachectl(On some installations the path may be different. In such cases, you have do a find)Original script---------------case $ARGV instart|stop|restart|graceful|graceful-stop)$HTTPD -k $ARGVERROR=$?;;Modified script---------------case $ARGV instart)LD_PRELOAD=/usr/lib/libtrellixsslagent.so $HTTPD -k $ARGV#$HTTPD -k $ARGVERROR=$?;;stop|restart|graceful|graceful-stop)$HTTPD -k $ARGVERROR=$?;;Restart the Apache
#apachectl stop; apachectl startFor Nginx Webserver:
Nginx is usually started by the command line
/usr/bin/nginxor/usr/sbin/nginx.Edit the startup command line and use
<bash>#LD_PRELOAD=/usr/lib/libtrellixsslagent.so /usr/bin/nginxor
<bash>#LD_PRELOAD=/usr/lib/libtrellixsslagent.so /usr/sbin/nginxOptional steps:
On most of the servers, syslog is configured to log till "INFO" level only. If LOG_DEBUG messages are to be logged, which is what the Agent uses to dump more information, syslog configuration needs modification.
Edit the file
/etc/rsyslog.confand search for the line similar to the line below:*.info;mail.none;news.none;authpriv.none;cron.none /var/log/messageschange it to
*.debug;mail.none;news.none;authpriv.none;cron.none /var/log/messagesFor CentOS server:
Install semanage utility using the below command:
yum install /usr/sbin/semanageCheck the ports assigned to Apache/HTTPD process:
semanage port -l | grep -w http_port_tExample:
[root@localhost Apurva]# semanage port -l | grep -w http_port_t http_port_t tcp 80, 81, 443, 488, 8008, 8009, 8443, 9000
Add port
8501to the list.Note
8501is the listening port in the Sensor. The apache process in the CentOS server needs to initiate a connection to port8501of the Sensor.semanage port -a -t http_port_t -p tcp 8501Verify that port
8501has been added to the list.Example:
[root@localhost Apurva]# semanage port -l | grep -w http_port_t http_port_t tcp 8501, 80, 81, 443, 488, 8008, 8009, 8443, 9000
Reload the system daemon and restart the Apache/HTTPD service.
Reload the system daemon using the command
root#systemctl daemon-reload.Restart the Apache/HTTPD service using the command
root#service httpd restart OR apachectl restart.