Configure custom certificates
You can provision custom Remote Collector certificates on both the Guardian and the Remote Collector sensors to replace the automatically generated self-signed certificates.
Before you begin
Make sure that you have:
- Both the certificate and the key file in privacy-enhanced mail (PEM) format
- A complete certificate chain
Important:
This feature is not supported in
containerized environments.
About this task
To add a private certificate authority (CA) to the system's trust store, see Install a CA certificate.
You must perform this procedure on both the Guardian and the Remote Collector using their respective certificates.
Procedure
- Change the name of the certificate file to rc_nozomi.crt
- Change the name of the key file to rc_nozomi.key
- Upload the certificate and key files to the sensor /data/tmp folder
-
To enable the certificate, enter this command:
n2os-addtlscert --rc rc_nozomi.crt rc_nozomi.key