On this screen, specify the settings for the web server you will use to host the Endpoint Application Control web console.
If Setup detects a Microsoft Internet Information Server (IIS) 7.0 or later server in your environment, then Microsoft IIS server and IIS virtual website will be enabled and selected by default.
Setup applies the settings on this screen only if there is no existing installation. If you upgrade or reinstall over an existing installation, Setup uses the settings from that installation.
Before selecting a web server, see the additional information on web servers at Web Server Considerations.
Enabling this feature may require you to import a server certificate authority (CA) to agent endpoints. You can use the automatically-created certificate and CA, or you can use your own certificate and public or private CA. Typically, you only need to import a private CA.
To learn more about TLS/SSL, see TLS/SSL Considerations.
To secure connections using Transport Layer Security (TLS) or Secure Sockets Layer (SSL), do the following:
Select Enable TLS/SSL. Setup automatically creates the required certificate.
To learn about TLS/SSL implementation in Endpoint Application Control, see TLS/SSL Considerations.
Optionally, add your own certificate and public or private CA to the Endpoint Application Control server certificates folder.
To replace the automatically-generated certificate, follow the steps to import a certificate for your web server type:
Web Server Type |
Steps |
---|---|
Apache Tomcat |
Do the following:
|
Microsoft Internet Information Server (IIS) |
In Windows Server 2008, do the following:
|
To use the automatically-created certificate or your own private certificate, import the CA.
For example, do one of the following:
Import to the Trusted Root Certification Authorities store for your domain.
See Microsoft Technet https://technet.microsoft.com/en-us/library/cc772491.aspx.
Import to specific Group Policy Objects.
See Microsoft Technet https://technet.microsoft.com/en-us/library/cc770315.aspx.
The following table lists the default port numbers for the Endpoint Application Control web server:
Web Server Selected |
HTTP Port |
HTTPS Port (TLS/SSL) |
Configurable |
---|---|---|---|
Apache Tomcat |
8080 |
4343 |
Yes |
Microsoft Internet Information Server (IIS) Default website |
80 |
443 |
|
Microsoft Internet Information Server (IIS) Virtual website |
8080 |
4343 |
Yes |