[KB8051] Migrate to a new certificate chain in ESET PROTECT On-Prem

Issue

  • You enabled advanced security and need to migrate to a new certificate chain
  • Your current certificates are expired and you need to migrate to a new certificate chain
  • You do not remember your current Certificate Authority (CA) passphrase and need to migrate to a new certificate chain

Solution

I. Create new CA and certificates

  1. Create a new CA, agent peer certificate and then create a new server peer certificate.

II. Migrate clients to a new Agent certificate

  1. Open ESET PROTECT On-Prem in your web browser and log in.


  2. Click Policies. Click Actions New

    Figure 1-1
  3. In the Basic section, type a Name.

    Figure 1-2
  4. Click Settings, select ESET Management Agent from the drop-down menu and click Change certificate.

    Figure 1-3
  5. Click Open certificate list.

    Figure 1-4
  6. Select the check box next to the agent certificate created in section I. Click OK.

    Figure 1-5
  7. Click OK.

    Figure 1-6
  8. Click Assign Assign.

    Figure 1-7
  9. Select the check box next to the groups or computers the new policy will apply to. Click OK.

    Figure 1-8
  10. Click Finish.

    Figure 1-9
 

III. Set new ESET PROTECT Server certificate

Before switching the server certificate

Before switching over to the new server certificate, allow time for all machines to check in to the management console and receive the new agent policy. 

  1. Open ESET PROTECT On-Prem in your web browser and log in.


  2. Click More Server SettingsChange certificate.

    Figure 2-1
  3. Click Open certificate list.

    Figure 2-2
  4. Select the check box next to the server certificate created in section I. Click OK.

    Figure 2-3
  5. Click Save.

    Figure 2-4
  6. Restart the ESET PROTECT Server service.