Kaspersky Security Center

Reissuing the Web Server certificate

July 1, 2024

ID 208265

The Web Server certificate used in Kaspersky Security Center Linux is required for publishing Network Agent installation packages that you subsequently download to managed devices, as well as for publishing iOS MDM profiles, iOS apps, and Kaspersky Endpoint Security for Mobile installation packages. Depending on the current application configuration, various certificates can function as the Web Server certificate (for more detail, see About Kaspersky Security Center Linux certificates).

If you have never specified your own custom certificate as the Web Server certificate in the Web Server section of the Administration Server properties window, the mobile certificate acts as the Web Server certificate. In this case, the Web Server certificate reissuance is performed through the reissuance of the mobile protocol itself.

To reissue the Web Server certificate when you have any mobile devices managed through the mobile protocol:

  1. Generate your custom certificate and prepare it for the usage in Kaspersky Security Center Linux. Check whether your custom certificate meets the requirements of Kaspersky Security Center Linux and the requirements for trusted certificates by Apple. If necessary, modify the certificate.

    You can use the kliossrvcertgen.exe utility for certificate generation.

  2. In the main menu, click the settings icon () next to the name of the required Administration Server.

    The Administration Server properties window opens.

  3. On the General tab, select the Web Server section.
  4. In the Over HTTP subsection, select the Specify another certificate option and click the Change certificate button.
  5. In the window that opens, in the Certificate type field select the type of your certificate:
    • If you have selected PKCS #12 container, click the Browse button next to the Certificate field and specify the certificate file on your hard drive. If the certificate file is password-protected, enter the password in the Password (if any) field.
    • If you have selected X.509 certificate, click the Browse button next to the Private key field and specify the private key on your hard drive. If the private key is password-protected, enter the password in the Password (if any) field.
  6. Click the Save button, then click OK.

    The window is closed.

  7. If necessary, in the Web Server HTTPS port field change the number of the HTTPS port for Web Server and click the Save button.

The Web Server certificate is reissued.

To reissue the Web Server certificate when you have no mobile devices managed through the mobile protocol:

  1. In the main menu, click the settings icon () next to the name of the required Administration Server.

    The Administration Server properties window opens.

  2. On the General tab, select the Certificates section.
  3. If you plan to continue using the certificate issued by Kaspersky Security Center, do the following:
    1. Select the Certificate issued through Administration Server option and click the Browse button.
    2. In the window that opens, in the Connection address and Activation term groups of settings, select the relevant options and click OK.

Alternatively, if you plan to use your own custom certificate, do the following:

  1. Check whether your custom certificate meets the requirements of Kaspersky Security Center Linux and the requirements for trusted certificates by Apple. If necessary, modify the certificate.
  2. Select the Other certificate option, click the Manage certificate button, and then in the window that opens, click the Browse button.
  3. In the window that opens, in the Certificate type field select the type of your certificate:
    • If you have selected PKCS #12 container, click the Browse button next to the Certificate field and specify the certificate file on your hard drive. If the certificate file is password-protected, enter the password in the Password (if any) field.
    • If you have selected X.509 certificate, click the Browse button next to the Private key field, and specify the private key on your hard drive. If the private key is password-protected, enter the password in the Password (if any) field.
  4. Click the Save button, then click OK.

The mobile certificate is reissued to be used as the Web Server certificate.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.