Jump to content

Recommended Posts

Antipova Anna
Posted

Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials.

Description and cautions

To replace the expiring certificate for mobile devices, you need to create a reserve certificate manually!

There is a problem with updating the certificate for mobile devices for KSC. So-as a mechanism for issuing a reserve certificate, which should replace the main one after its expiration.

If there is an automatic procedure for creating and replacing an expiring certificate for the main KSC server certificate (klserver.cer), then for mobile devices the issue of a reserve certificate (klsrvmob.cer2) must be issuing manually.

Details

This is a simple procedure:

1) Open Administration Server properties

image.png.96e5bf062c6e3a934db534f30248b9ed.png

2) Select "Administration Server connection settings → Certificates"

image.thumb.png.9834dc96b53a1ab0ae570cec67ff86d0.png

3) Check the date when the current certificate expires. 

4) Press "Reissue..." button and select "After this period expires" option.

image.thumb.png.f44f301b718d7825c10e77bb9cbcf8a4.png

5) Enter the number of days after which the new certificate will be applied. We recommend choosing at least 30 days so that all devices have time to contact the server and get a new certificate.

6) An additional field should appear in which the new certificate and the date of its application will be indicated.

7) Additionally, you can check that the certificate was created in the directory "C:\ProgramData\KasperskyLab\adminkit\1093\cert"

image.png.15346f971e21571dc08f10d19e762bae.png

You can also create a reserve certificate via the command line, using the klsetsrvcert utility with "-t MR" option for generate reserve certificate and "-f DD-MM-YYYY hh:mm"  to specify the date of application of the new certificate.

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...