cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Certificates used by ePO

Jump to solution

What are the certificates in use by ePO that could be issued by an internal CA? We are doing an exercise to renew any certs that are close to expiry, and found 2 certs on our CA that are issued to the ePO server. I could only find information for one type of cert, which is the ePO web console cert.

2 Solutions

Accepted Solutions
Hawkmoon
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: Certificates used by ePO

Jump to solution

Hi Wu_Yuxuan,

Maybe this will help?

1. Open up a command prompt and type in mmc.exe.
    (This will open up a mmc console.)

2. Click on file->Add/remove a snapin. Next click the Add button.
    (This brings up a list of standalone snapins.)

3. Choose the Certificates snapin.
    a. Select Computer Account. We store all our certificates to the system.
    b. Choose Local Computer

4. Select 'Close' and 'Ok'.

You should now have an mmc console with the 'Certificates (Local Computer)' in the mmc console. The ePO certificates are located in the following locations:

    • Orion_CA_<EPOServer Name>
        - This is located in the Certificates->Trusted Root Certification Authorities->Certificates.
    • AH_CA_<EPOServer Name>
        - This is located in the Certificates->Intermediate Certification Authorities->Certificates.
    • AH_<Agent Handler Server Name>
        - This is located in the Certificates->Personal->Certificates.

 

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 5

Re: Certificates used by ePO

Jump to solution
You are correct, the only cert that can be changed is the browser cert.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

4 Replies
Hawkmoon
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: Certificates used by ePO

Jump to solution

Hi Wu_Yuxuan,

Maybe this will help?

1. Open up a command prompt and type in mmc.exe.
    (This will open up a mmc console.)

2. Click on file->Add/remove a snapin. Next click the Add button.
    (This brings up a list of standalone snapins.)

3. Choose the Certificates snapin.
    a. Select Computer Account. We store all our certificates to the system.
    b. Choose Local Computer

4. Select 'Close' and 'Ok'.

You should now have an mmc console with the 'Certificates (Local Computer)' in the mmc console. The ePO certificates are located in the following locations:

    • Orion_CA_<EPOServer Name>
        - This is located in the Certificates->Trusted Root Certification Authorities->Certificates.
    • AH_CA_<EPOServer Name>
        - This is located in the Certificates->Intermediate Certification Authorities->Certificates.
    • AH_<Agent Handler Server Name>
        - This is located in the Certificates->Personal->Certificates.

 

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Hawkmoon
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 5

Re: Certificates used by ePO

Jump to solution

The following is for information. 😉😀

How to regenerate the certificates used by the McAfee ePO server service
Technical Articles ID: KB90760

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

cdinet
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 5

Re: Certificates used by ePO

Jump to solution
You are correct, the only cert that can be changed is the browser cert.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Certificates used by ePO

Jump to solution
Noted on the 3 ePO self-signed certs and the 1 CA-issued web console cert. Thanks for the help, Hawkmoon and cdinet.
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community