Create a certificate for the Management Server using external certificate management

Create a certificate request for the Management Server, export and sign the certificate request using the external CA, then import the signed certificate for the Management Server.

Steps

  1. Log in to the console with the user account created during the installation.
  2. Create a certificate signing request for the Management Server.
    Enter the following command to create certificate request to the /tmp/mgmt.csr file:
    sudo /usr/local/forcepoint/smc/bin/sgCertifyMgtSrv.sh mode=ext-pki-init key-size=384
    dn="CN=MyMgmt,C=US,OU=MyCompany" dns="my-mgmt" csr-out=/tmp/mgmt.csr
     
    Note: Key-size parameter of 521 bits is also acceptable if the configuration is not intended to be compatible with Commercial Solutions for Classified configuration.
    Important:
    • Replace the 'dn' field value with an appropriate descriptive distinguished name for your environment.
    • Replace the 'dns' field value with a suitable and unique domain name that identifies the management server in your environment.
    • The CSfC compatible configuration can be disabled by generating a new Management Server certificate with a key size parameter of 521. The new configuration will then be Common Criteria compatible instead.
  3. Export the generated CSR using scp.
    Enter the following command:
    scp /tmp/mgmt.csr <user>@<host>:<path>
     
  4. Sign the CSR externally and import the certificates using scp. Any intermediate certificates must be bundled into the same file with the signed leaf certificate.
    Enter the following command:
    scp <user>@<host>:<path>/mgmt.cert.pem /tmp/
    chmod a+r /tmp/mgmt.cert.pem
    scp <user>@<host>:<path>/ca.cert.pem /tmp/
    chmod a+r /tmp/ca.cert.pem
    sudo /usr/local/forcepoint/smc/bin/sgCertifyMgtSrv.sh mode=ext-pki-import crt-in=/
    tmp/mgmt.cert.pem ca-file=/tmp/ca.cert.pem
     
  5. Start the Management Server.
    Enter the following command:
    sudo daemon-ctl restart sgMgtServer

Next steps

Install the SMC Client, and then create a certificate for the Log Server.
Important:
  • Installing the SMC Client is optional. You can access SMC by using SMC Web Access or by installing the SMC Client to a separate host. By default, the SMC Web Access is enabled when the management server starts.
  • The SMC Client can be accessed using a web browser on https port 8085 on the SMC Appliance. For example, if the SMC Appliance is configured with the IP address 192.0.2.1, the SMC Client can be accessed using the URL https://192.0.2.1:8085/ in a web browser.