Configuring trusted connection with KATA Central Node
This section provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.
To configure trusted connection between Kaspersky Endpoint Agent and KATA Central Node, perform the following actions on Kaspersky Endpoint Agent side:
Open Kaspersky Security Center Administration Console.
In the console tree, open the Policies folder.
Select Kaspersky Endpoint Agent policy and open its properties window in one of the following ways:
Double-click the policy name.
Select Properties in the policy context menu.
Select the Configure policy settings item in the right part of the window.
In the Telemetry collection servers section, select the KATA integration subsection.
In the Connection settings group, select the Use pinned certificate to secure connection check box.
Click the Add new TLS certificate button.
The Adding TLS certificate window will open.
Perform one of the following actions to add a TLS certificate:
Add a certificate file. Click Browse, and in the window that opens, select the certificate file and click Open.
Copy and paste the contents of the certificate file to the Paste TLS certificate data field.
Kaspersky Endpoint Agent may have only one KATA server TLS certificate. If you have added a TLS certificate before and then add a TLS certificate once again, only the last added certificate is valid.
Click Add.
Information about the added TLS certificate is shown in the TLS certificate data group of settings.
If you want to configure additional connection protection by a user certificate, click the Add client certificate button.
In the Add client certificate window that opens, do the following:
Select the Secure connection with client certificate check box.
Click the Upload button and in the window that opens select the PFX archive and click Open.
Enter the password for the PFX archive.
Click OK.
In the upper right corner of the settings group, change the switch from Policy not enforced to Under policy.
Click OK.
The trusted connection to KATA server is now configured.