The Certificates pane

The Certificates pane simplifies handling of trusted and system certificates in Forescout.

The Certificates pane replaces previously used fstools features. Certificates used in earlier versions of eyeSight are automatically migrated, along with their scopes, to the System Certificates and Trusted Certificates tables.

Each certificate is associated with one or more Forescout services, or with applications running on one or more eyeSight devices. This allows different certificates to be used for different Forescout sub-systems running on different devices.

Access the Certificates pane at Tools > Options > Certificates.

images/image840.png

Certificate general settings

Configure general options for certificates defined in Forescout at Tools > Options > Certificates.

Email Notice for Certificate Expiration

Enable and configure automatic emails when certificates near expiration. Select one of the following options.

Send only to CounterACT Operator
Send email only to the eyeSight operator at the email shown.
Send to CounterACT Operator and to
Send email to the eyeSight operator, and to the specified email address.

Specify time intervals for email notification.

Send initial notice (prior to expiration)
The time of the first reminder email, relative to the certificate expiration date. The default is 60 days.
Send repeat notices every
The time interval at which additional reminders are sent. The default is two weeks.
Email Notice for Certificate Expiration

Enable and configure automatic emails when certificates near expiration. Select one of the following options.

Send only to CounterACT Operator
Send email only to the eyeSight operator at the email shown.
Send to CounterACT Operator and to
Send email to the eyeSight operator, and to the specified email address.

Specify time intervals for email notification.

Send initial notice (prior to expiration)
The time of the first reminder email, relative to the certificate expiration date. The default is 60 days.
Send repeat notices every
The time interval at which additional reminders are sent. The default is two weeks.

Ongoing TLS sessions

Re-verify TLS sessions every

The time interval at which Forescout verifies the certificate of existing TLS sessions. Ongoing TLS sessions may be kept alive for performance reasons - for example, the User Directory plugin connection to the Active Directory server is used more many requests. By default, this option is disabled.

Certificate scope settings

Scope settings determine which eyeSight sub-systems and devices can accept or present a certificate.

Email Notice for Certificate Expiration

Enable and configure automatic emails when certificates near expiration. Select one of the following options.

Send only to CounterACT Operator
Send email only to the eyeSight operator at the email shown.
Send to CounterACT Operator and to
Send email to the eyeSight operator, and to the specified email address.

Specify time intervals for email notification.

Send initial notice (prior to expiration)
The time of the first reminder email, relative to the certificate expiration date. The default is 60 days.
Send repeat notices every
The time interval at which additional reminders are sent. The default is two weeks.

Certificate precedence between Appliance and Enterprise Manager

When you add an Appliance to an Enterprise Manager, the certificates of one may take precedence over the other.

When the first Appliance is added to an Enterprise Manager, you can copy the full Appliance configuration, including certificates, to the Enterprise Manager, or define certificates from scratch.

When another Appliance is added to an Enterprise Manager:

  • Typically the Enterprise Manager has no certificates with a scope that includes the Appliance. The Appliance certificates are pushed to the Enterprise Manager and scoped for the Appliance.
  • When the Enterprise Manager has certificates whose scope covers the Appliance (for example, when the configured scope is All Devices) , the Enterprise Manager certificates take precedence, and the Appliance certificates are removed. To retain the Appliance certificates, export them to a file before you add the Appliance to the Enterprise Manager, and import them after the Appliance is added.

Manage trusted certificates

eyeSight components and services use the trusted certificates defined in Forescout to authenticate certificates presented by external applications.

Certificates are trusted only if the issuer chain they present ends with a trusted certificate authority (CA). You can define the scope of services or devices in your eyeSight deployment for which each certificate is accepted.

Manage system certificates

Forescout presents system certificates to external services and applications.

Ensure that each subsystem is scoped to the correct certificate on every device on which it runs.