The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Migrating the Manager-Sensor trust from self-signed to CA-signed certificate chain

Prev Next

The high-level steps to establish trust between the Manager and the Sensor using CA-signed certificate chain are given below. Perform these steps to:

  • Provision the Manager with its CA-signed certificate

  • Use the Manager to provision the Sensor with its CA-signed certificate

  • Migrate the trust based on the existing self-signed certificates to the provisioned CA-signed certificates between the Manager and the Sensor

    Note

    For CA migration in an MDR setup, you must first create an MDR pair, then create Certificate Signing Request (CSR) and migrate to CA.

  1. Generate CSR for the Manager and Sensors.

  2. Export the CSR for both the Manager and Sensors and send it to a CA of your choice.

  3. The CA processes the CSR and sends a CA-signed certificate.

    Note

    For validations for CA-signed certificate, see Considerations for CA-signed certificate chain.

  4. After receiving the CA-signed certificate chain, import the certificate chain to the Manager. You need to migrate the Manager to CA-signed certificate chain before migrating the Sensors.

    Note

    Migrating the Manager to CA-signed certificate chain is a one time activity. Once the Manager is migrated to the CA-signed certificate chain, you must migrate the Sensors that are attached to the Manager.

  5. The Manager validates its CA-signed certificate chain against its generated CSR.

  6. From the Manager, import the CA-signed certificate chain to the Sensors managed by the Manager.

  7. The Manager validates the Sensor's CA-signed certificate chain against its generated CSR.

  8. If the validation is successful, from the Manager change the active certificate to use the CA-signed certificate chain to establish trust between Manager and Sensor. The switch is completed one Sensor at a time.

This migration is applicable to the Manager and all Sensors managed by the Manager. The Manager can establish trust with Sensors using either self-signed certificate or CA-signed certificate chain.

Note

The trust establishment works when both the Manager and Sensors are using the CA-signed certificate chain or when both are using self-signed certificate.