Generate SSL certificates
Generate new SSL certificates for securing communication between AgentX Server and AgentX Clients.
Prerequisites
AgentX Server installed in Logpoint
AgentX Manager installed in Logpoint
Administrator access to Logpoint
In distributed Logpoint setups, you must generate certificates on the Search Head
Procedure
Go to Settings > Configuration and select AgentX.
Select Certificates.
Select Generate.
In the confirmation dialog, select Yes to confirm certificate generation.
After generation completes, select Download to download the client certificates (sslagent.cert and sslagent.key).
Replace existing certificates on all AgentX Clients with the downloaded certificates.
Expected outcome
AgentX generates three new certificates:
rootCA.pem - Root Certificate Authority certificate (synced automatically to AgentX Server)
sslagent.cert - Client authentication certificate (must be downloaded)
sslagent.key - Client certificate key (must be downloaded)
Existing agents continue using old certificates until you replace them.
Verification
Go to Settings > Configuration > AgentX > Certificates.
Verify that the certificate generation timestamp is updated.
After replacing certificates on agents:
Go to Settings > Configuration > AgentX > Agents.
Verify that agents reconnect successfully and appear in the agents list.
Replace certificates on Windows agents
Navigate to the AgentX Client installation directory (default:
C:\Program Files (x86)\ossec-agent\cert).Back up the existing certificate files.
Copy the downloaded
sslagent.certandsslagent.keyfiles to thecertdirectory.Restart the AgentX Client service:
Open Services (services.msc)
Right-click the AgentX or OSSEC service
Select Restart
Replace certificates on Linux agents
Navigate to the certificate directory:
Back up the existing certificate files:
Copy the downloaded certificate files to the directory.
Restart the wazuh-agent service:
Configuration guidelines
Generate certificates before large deployments If you plan to deploy AgentX to many endpoints, generate custom certificates before installation to avoid replacing default certificates on all agents later.
In distributed mode, certificates sync automatically When operating in distributed mode, AgentX automatically syncs rootCA.pem to all Logpoint nodes in the cluster. You only need to generate certificates once on the Search Head.
New agents after generation use old certificates Agents installed after certificate generation still receive the default certificates during installation. You must manually replace certificates on these agents as well.
Keep client certificates secure Store the downloaded client certificates securely. Anyone with access to these certificates can authenticate agents to your AgentX Server.
Next steps
Last updated
Was this helpful?