HCL BigFix digital signature

Hello,

Kindly advise how we can obtain the HCL BigFix digital signature/certificate that can be used to verify and trust BigFix components.

We are currently facing an issue with BigFix BESHelper. When we attempted to install BESHelper on an endpoint, Trend Micro Apex One blocked the installation because the component was reported as having no trusted digital signature.

To resolve the issue temporarily, we had to provide the Trend Micro team with the HCL BigFix digital signature/certificate so that they could add it to the trusted list and allow BigFix components to run.

Could you please advise:

  1. Where can we obtain the official HCL BigFix digital signature/certificate?

  2. Which certificate or public key should be added to Trend Micro Apex One to trust BigFix components such as BESHelper?

  3. Is there an official HCL-provided certificate or signer information that we can use for this purpose?

BR,

Mohamed

I started to write a very different post about retrieving a certificate bundle from your root server before I reread your post and realized you're talking about something different.

You're referring to the 'BES Client Helper Service'? You should probably just avoid using it entirely, do you have a reason for it? That tool was last updated in 2014, I was surprised to find I can still locate it in the BES Support site though.

edit: and the binary is unsigned entirely.

Unrelated to OP ask, I didn’t know the helper tool was that old / abandoned. I have been thinking of proposing to implement it on Windows servers to help with the occasional service stop/hang :slight_smile: I have installed it on a small handful of problematic servers, but that’s it.

I will go back to something that would be cross platorm then :smiley: (Nix + Win)

thx!