IT Management Suite

 View Only
  • 1.  Add certificate to Trusted Root Certification / Certificates

    Posted 14 days ago

    Is it possible to install / push a .crt to local computer certificates in Trusted Root Certification / Certificates on W11?

    Thank you!



    ------------------------------
    Giles
    ------------------------------


  • 2.  RE: Add certificate to Trusted Root Certification / Certificates

    Broadcom Employee
    Posted 12 days ago

    Good morning Iskyfly!

    For required certificates installation, you can try import them in default NS Communication profile
    Import there required certificates and save changes 

    After next policy refresh, all managed computers will install this certificate.

    There is information about how to get list of all installed certificates by Symantec Management Agent from command line
    https://community.broadcom.com/symantecenterprise/communities/community-home/digestviewer/viewthread?GroupId=2821&MessageKey=8f20140a-0104-4c05-8fa3-7e665c854e8b&CommunityKey=bf23126f-6eab-4bbe-965d-e26838c079e0 

    All installed certificates can be viewed in SMA UI, but need to enable "diagnostics" mode for Symantec Management Agent:
    C:\Program Files\Altiris\Altiris Agent>AeXNSAgent.exe /diags

    Now in SMA UI need to activate "Certificates" page

    Best regards,
    IP.




  • 3.  RE: Add certificate to Trusted Root Certification / Certificates

    Posted 11 days ago

    Hello Igor!

    Thank you for your reply.

    I should have clarified-

    The certificate is not for Altiris. What I meant was, can I use Altiris / ITMS to push / install a .crt for an application (Touchnet Point of Sale Controller). The POSC install is an MSI which installs silently on its own with no problems. The .CRT file needs to be added to Trusted Root Certification  / Certficates for the local computer.

    Can this be scripted in Altiris / ITMS ?

    Thank you!



    ------------------------------
    Giles
    ------------------------------



  • 4.  RE: Add certificate to Trusted Root Certification / Certificates

    Broadcom Employee
    Posted 11 days ago

    Hello Iskyfly!

    1. In previous comment, I meant that Symantec Management Agent shows installed certificates that were installed only by Agent itself (certificates that were imported in NS Communication profile and not related to Altiris only) 
    Otherwise Admin can import any required certificate(s) in NS Communication profile and these certificates will be installed on managed Windows computers.

    2. Symantec Management Agent can install required certificates using "Run Script" tasks
    Simple example using powershell

    As result, this certificate is installed in trusted root on client computer

    Best regards,
    IP.




  • 5.  RE: Add certificate to Trusted Root Certification / Certificates

    Broadcom Employee
    Posted 10 days ago

    There is a Custom inventory available to get information about installed certificates on client devices
    https://community.broadcom.com/symantecenterprise/viewdocument/custom-inventory-to-get-installed-c?CommunityKey=bf23126f-6eab-4bbe-965d-e26838c079e0&tab=librarydocuments




  • 6.  RE: Add certificate to Trusted Root Certification / Certificates

    Posted 9 days ago

    Thank you very much Igor! I should have read your first reply a little more closely. Thank you also for the custom inventory info!



    ------------------------------
    Giles
    ------------------------------