Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. During the import process, make sure to check Mark this key as exportable.

  2. Complete the wizard, and the client certificate will be added to the Personal store.

...

Step 4:

...

Verification

  • Verify the Certificates:

  1. Navigate to Trusted Root Certification Authorities, Intermediate Certification Authorities (if used) and Personal

  2. Confirm that the certificates are properly listed.

  • Verify the Snare Agent:

  1. Go to Security Certificates Destination Configuration pagein Agent GUI and confirm , select “mTLS” in Protocol to enable the mTLS Certificate field. Confirm that the imported client certificate is listed in the list. Following figure shows that a client certificate named “Client Cert ml” which was imported is in the list.

...

  1. mTLS_certList.pngImage Added

Conclusion

You have now successfully imported both the trusted certificate chain and the client certificate with the private key exportable into the Windows Certificate Store. This setup is ready for mutual TLS communication, with the intermediate certificate being optional depending on your server's configuration.