The high-level steps to establish trust between the Manager and the Sensor using CA-signed certificate chain are given below. Perform these steps to:
Provision the Manager with its CA-signed certificate
Use the Manager to provision the Sensor with its CA-signed certificate
Migrate the trust based on the existing self-signed certificates to the provisioned CA-signed certificates between the Manager and the Sensor
Note
For CA migration in an MDR setup, you must first create an MDR pair, then create Certificate Signing Request (CSR) and migrate to CA.
Generate CSR for the Manager and Sensors.
Export the CSR for both the Manager and Sensors and send it to a CA of your choice.
The CA processes the CSR and sends a CA-signed certificate.
Note
For validations for CA-signed certificate, see Considerations for CA-signed certificate chain.
After receiving the CA-signed certificate chain, import the certificate chain to the Manager. You need to migrate the Manager to CA-signed certificate chain before migrating the Sensors.
Note
Migrating the Manager to CA-signed certificate chain is a one time activity. Once the Manager is migrated to the CA-signed certificate chain, you must migrate the Sensors that are attached to the Manager.
The Manager validates its CA-signed certificate chain against its generated CSR.
From the Manager, import the CA-signed certificate chain to the Sensors managed by the Manager.
The Manager validates the Sensor's CA-signed certificate chain against its generated CSR.
If the validation is successful, from the Manager change the active certificate to use the CA-signed certificate chain to establish trust between Manager and Sensor. The switch is completed one Sensor at a time.
This migration is applicable to the Manager and all Sensors managed by the Manager. The Manager can establish trust with Sensors using either self-signed certificate or CA-signed certificate chain.
Note
The trust establishment works when both the Manager and Sensors are using the CA-signed certificate chain or when both are using self-signed certificate.