Configuring trusted connection with KICS for Networks
This Help provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
The functionality described in this section will be available after the release of Kaspersky Industrial CyberSecurity for Nodes 3.0.
To configure trusted connection between Kaspersky Endpoint Agent and KICS for Networks, perform the following actions on Kaspersky Endpoint Agent side:
In the main Kaspersky Security Center Web Console window select Devices → Policies and profiles.
Select the policy you want to configure.
In the <Policy name> window that opens, select the Application settings tab.
In the Telemetry collection servers section, select KICS for Networks integration.
The KICS for Networks integration window opens.
In the Connection settings group, select the Use pinned certificate to secure connection check box.
Click the Add new TLS certificate button.
The window for adding a new TLS certificate opens.
Perform one of the following actions to add a TLS certificate:
Add a certificate file. Click Upload, and in the window that opens, select the certificate file and click Open.
Copy and paste the contents of the certificate file to the TLS certificate data field.
Kaspersky Endpoint Agent may have only one TLS certificate for the KICS for Networks server. If you have added a TLS certificate before and then add a TLS certificate once again, only the last added certificate is valid.
Click OK.
Information about the added TLS certificate is shown in the TLS certificate data group of settings.
If you want to configure additional connection protection by a user certificate, do the following:
Select the Secure connection with client certificate check box.
Click the Upload your crypto container button.
In the window that opens select the PFX archive and click Open.
In the Crypto container password field, enter the password for the PFX archive.
Click OK.
In the upper right corner of the settings group, change the switch from Undefined to Enforce.
The default switch position is Enforce.
Click OK.
Trusted connection to KICS for Networks server is configured.