Issue
- Enable OpenSSL 3.x support for ESET PROTECT On-Prem for Linux
- Certificate error for agents using older operating systems
- Upgrade OpenSSL 1.1.1 to OpenSSL 3.x
- See more information on Advanced Security settings
Solution
Certificate error for agents using older operating systems
You receive the following error after OpenSSL 3.x, the ESET PROTECT Server and ESET PROTECT On-Prem have been installed:
-
Click More → Settings, expand Connection, disable the toggle next to Advanced security and restart the server service.
-
Click More → Settings, expand Connection, enable the toggle next to Advanced security and restart the server service.
-
Select the new certificate when generating installers or deploying agents using the agent deployment task.
- Create a new agent policy to distribute the new certificates to clients on an older operating system.
Upgrade OpenSSL 1.1.1 to OpenSSL 3.x
Existing ESET PROTECT On-Prem environments that use OpenSSL 1.1.1 can upgrade to OpenSSL 3.x.
- Install OpenSSL 3.x on the server.
- Rerun the server installation command to link to the OpenSSL 3 libraries.
- Create Certificate Authority and Peer Certificate. The new certificates will facilitate the OpenSSL 3.x algorithms.
- Create a new agent policy to distribute the new certificates to eligible clients. The original certificates are still available and can connect older devices that do not recognize the new CA.