FireEye - Web interface does not use the system self-signed certificate

Information

A certificate from a trusted CA allows for secure identification of the appliance to clients. Certificates may be loaded through HTTP/FTP/TFTP or SCP.

Solution

Generate a public/private key pair for the appliance. Once it is installed set it as the default identity certificate. Edit the configuration and add these lines:\n

webui ssl install certificate <url> private-key <url> [ca-certificate <url>]\n
crypto certificate default-cert name <name_of_new_cert>

Item Details

Audit Name: TNS FireEye

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)

Plugin: FireEye

Control ID: 2faf9d033e7cd8ea65c7e6b99dd83d5ff08669769c28ce859662e643931dc5a2