Configure CylanceHYBRID
CylanceHYBRID
Take a snapshot of the virtual machine that hosts the application in case the configuration fails, including invalid SSL certificate uploads. This will allow you to revert to the snapshot instead of having to reinstall the application.
- In theCylance Endpoint Securitymanagement console, clickSettings > Application.
- In theInstallation Tokenfield, copy the token.
- In theCylanceHYBRIDconsole (for example, login.hybrid.com:8800), in theApplicationsection, clickCylanceHYBRID. Make sure that the status is Ready.
- On the Welcome screen, clickLet’s Get Started. The Import Hybrid Config page displays.
- If you want to import aCylanceHYBRIDconfiguration file from an existingCylanceHYBRIDinstance, do the following sub-steps. For more information, see Importing a CylanceHYBRID configuration. Otherwise, continue to Step 6.
- EnableImport.
- Drag and drop yourCylanceHYBRIDconfiguration file, or browse to the file and select it.
- ClickSave & Continue.
- Perform one of the following tasks:TaskStepsGenerate a certificate signing request (CSR) that will be submitted to a certificate authority (CA) to use with theCylanceHYBRIDapplication.
- Fill in the form:
- In theCommon Namefield, enter the common name, derived from the fully qualified domain name (FQDN) for the application. For example, if the FQDN is https://hybrid.cylance.com, the common name is hybrid.cylance.com.
- In theSubject Alternative Namefield, enter any alternative names to use for the application, such as hybrid-alt.cylance.com. The Common Name will be added automatically as a Subject Alternative Name.
- In theOrganization Namefield, enter the legal name of the organization.
- In theOrganizational Unitfield, enter the unit name. This could be a department name.
- In theCityfield, enter the city where the organization is located.
- In theState / Provincefield, enter the state or province where the organization is located. Do not use an abbreviation.
- In theCountryfield, enter the two-letter ISO abbreviation for the country.
- ClickGenerate CSR. This creates acert_request.csrfile in the Downloads folder. Send this file to your CA who should then send back an SSL certificate.Example:hybrid.cylance.crt.After you generate the CSR, the text at the top of the page changes to a pending status and includes a link where you can re-download the CSR and Step 2 displays at the bottom of the page.If you clickGenerate CSRagain, a new private key will be generated, and you will need to provide the latest CSR to the CA.
- In theStep 2: Upload certificate from CAbox, upload your SSL certificate.
For more information on a possible certificate issue, visit support.blackberry.com/community to read article 98224.Upload an SSL certificate and key generated on a computer other than the one that hosts theCylanceHYBRIDapplication.- Turn offGenerate private key and CSR. For more information on certificate guidelines, see our Certificate Guidelines.
- Drag and drop the certificate in theUpload certificatebox, or clickBrowse for a fileand select the certificate.
- Drag and drop the key in theUpload keybox, or clickBrowse for a fileand select the key.
(Optional) To have theCylanceHYBRIDapplication and status page use the same certificate as theCylanceHYBRIDadmin console:- Turn offGenerate private key and CSR.
- Turn onUse CylanceHYBRID admin console TLS certificate and key.
- ClickSave.
- ClickSave & Continue. TheActive DirectoryIntegration page displays.
- To disableActive DirectoryIntegration or to configure it after the initial setup of theCylanceHYBRIDapplication, turn offUse Active Directoryand go to step 11. For more information, see Using the CylanceHYBRID Status page.To addActive Directory/LDAP Integration, do the following:
- In theActive Directory Hostfield, enter the FQDN of the server that hosts Active Directory. This is a TLS requirement. If you enter an IP address for an LDAP server or the hostname instead of an FQDN, the configuration will fail. The FQDN must be configured in DNS.
- In thePortfield, enter the port number of the LDAP server.
- In theBase DNfield, enter the base distinguished name (DN) used as a base for the LDAP search to look for the user DN.
- In theGroup DNfield, enter the group DN used to perform an LDAP search to check if the user is a member of the group DN.
- In theUpload certificate to enable TLSfield, upload the SSL certificate used to perform a TLS connection when binding to the LDAP server. The certificate must be Base64 encoded.
- ClickTest Connection. A TestActive DirectoryConnection dialog displays.
- Enter a username and password and clickTest Connection. A message displays informing you that the connection was successful. If the connection failed, use the red text that appears on the dialog to troubleshoot and resolve the issue.To test the connection, use either the UPN login or sAMAccountName login:UPN Login Example:username@domainname.com(hadmin@onprem-cylance.com)sAMAccountName Login Example:domain\username(onprem-cylance\hadmin)
- ClickSave & Continue. The Set a password to access theCylanceHYBRIDStatus page displays.
- Enter and confirm your new password, and clickSave & Continue. Follow the password requirements. TheConfiguration Step 1 of 2: Enter Infopage displays.Ensure that you note down this password. Currently, there is no mechanism to reset or recover the password.
- Enter or paste your Installation Token.
- Enter a Device Name. This name will appear in theCylance Endpoint Securityconsole as a device.
- Type an FQDN for the virtual machine that hosts theCylanceHYBRIDapplication. The FQDN must match the one in the DNS entry. For example, an FQDN could be login.hybrid.com or hybrid.com.
- To include a proxy server, turn onConnect Appliance to Proxy. Enter the proxy-server information, including a proxy username and password.
- ClickSave & Continue. TheConfiguration Step 2 of 2: Confirm Infopage displays.
- If yourCylanceHYBRIDsetup information is correct, clickConfirm & Finish. TheCylanceHYBRIDSetup Complete page displays.
- ClickGo to Status Page. You are automatically signed in to theCylanceHYBRIDStatus page. For future sign ins, theCylanceHYBRIDusername iscylance.
When you have finished configuring the
CylanceHYBRID
application, it will appear in your Cylance Endpoint Security
management console, under Devices, with the Device Name that you assigned in Step 12.