IT Management Suite

 View Only
  • 1.  Script for certificate installation.

    Posted Mar 24, 2015 08:50 AM

    Any one have script for installing Symantec web gatewate certificate on client machine through the altiris.

    Kindly help me for installing SWG certificate through Altiris.



  • 2.  RE: Script for certificate installation.

    Posted Apr 28, 2015 11:27 PM
    Sangita, Is there a reason why you can't use group policy for this? There alternative is to do an offline client package as described here. https://www-secure.symantec.com/connect/forums/how-install-cem-agent-no-tray-icon Which will push the certificate as well


  • 3.  RE: Script for certificate installation.

    Posted Apr 29, 2015 01:28 AM

    You cannot so it via group policy The standard practice is to create the Offline client pakage so avoid issue w.r.t to migrations and upgrade.

    Refer

    https://support.symantec.com/en_US/article.TECH227638.html



  • 4.  RE: Script for certificate installation.

    Posted Apr 29, 2015 04:38 PM

    The offline client package is only needed if the machine you are installing to is not on the same network as the SMP.  If it is on the same network (I'm assuming it is since you are asking for a script to install it via Altiris), it is not necessary to deploy the certificate seperately.   The appropriate certificates will be automatically installed when you configure CEM for your platform as long as you target the machines properly and direct them to use HTTPS. 

    If you have attempted this and it isn't working, you may have missed a step.  This document walks you through the steps.  
    https://support.symantec.com/en_US/article.DOC7049.html

     



  • 5.  RE: Script for certificate installation.

    Posted May 16, 2015 07:39 PM
    All I should have been more clear. The Root CA that actually signed the gateway certificate can be deployed via GPO. For example, if you have an SSL certificate signed by GODaddy, you can deploy the rest of the chain that way. As mentioned before, if you have a machine that is off network or cannot communicate directly with the bs, there is an offline package but connectivity should be solid on network prior to trying this.