Appendix B: Configuring Your Server to use SSL
During installation of the Ivanti Endpoint Security server, you can configure Ivanti Endpoint Security to use SSL for server to agent communication after obtaining an SSL certificate from a trust provider.
Prerequisites:
-
You must obtain a certificate from a root certificate authority.
Obtaining a trusted SSL certificate can take several days. Therefore, Ivanti recommends obtaining an SSL certificate before installing Ivanti Endpoint Security. Certificates can be obtained from trust providers such as Verisign Inc. (www.verisign.com) or Entrust (www.entrust.com).
Configuring SSL
Associate your certificate with the Ivanti Endpoint Security (Ivanti Endpoint Security) Web site in your server's Internet Information Services (IIS) Manager.
The first portion of this procedure is performed before installation of Ivanti Endpoint Security, and the second portion is performed following installation of Ivanti Endpoint Security.
Important: If you are installing Ivanti Endpoint Security on a server that already hosts a Web site, a different procedure must be used for SSL configuration. For additional information, refer to https://forums.ivanti.com/s/article/L-E-M-S-S-One-of-the-IP-Port-combinations-for-site-67-has-already-been-configured-to-be-used-by-another-program for additional guidance.
- If necessary, import your certificate.
To import your certificate, complete the following substeps.
- Open Internet Information Services (IIS) Manager, which can be found in Administrative Tools within Control Panel.
Internet Information Services (IIS) Manager opens. - From the tree, select your Ivanti Endpoint Security server.
- In the main pane, scroll to the IIS section and double-click Server Certificates.
The Server Certificates page opens. - Click the Import link.
The Import Certificate dialog opens. - Click the Elipses button ( ... ), browse to your certificate, and click Open.
You may have to edit the File name type list to see your certificate. - Type the certificate Password.
- Click OK.
- Open Internet Information Services (IIS) Manager, which can be found in Administrative Tools within Control Panel.
- Assign the certificate to the default Web site.
To assign the certificate, complete the following substeps. - Complete one of the Ivanti Endpoint Security installation procedures listed in Selecting an Installation Method.
While installing Ivanti Endpoint Security, select the Use SSL security for Patch agent communication with the server check box.
Name resolution of the server, endpoints, and the root certificate authority is required to use SSL.
- Assign the certificate to the Ivanti Endpoint Security Web site.
Complete the following substeps to assign the certificate.- Open Internet Information Services (IIS) Manager, which can be found in Administrative Tools within Control Panel.
Internet Information Services (IIS) Manager opens. - From the tree, select Ivanti Web site (Server Name > Sites > Ivanti).
- Click the Bindings link.
The Site Bindings dialog opens. - Click Add.
The Add Site Binding dialog opens. - From the Type list, select https.
- From the SSL certificate list, select your certificate.
- Click OK.
- Click Close.
- Open Internet Information Services (IIS) Manager, which can be found in Administrative Tools within Control Panel.
- Configure the Web site to accept only SSL connections.
- In the main pane, scroll to the IIS section.
- Double-click SSL Settings.
- Select the Require SSL check box.
- Click Apply.
Your server is now configured for SSL communication.
- Complete Logging In to Ivanti Endpoint Security.
- Complete Setting Up Ivanti Endpoint Security.
- After you have completed setup, edit your global configuration policy set and ensure Use SSL for agent to server communication is True.