This document explains the issue of agent communication failure due to SAN mismatch when updating NAT FQDN and importing a new certificate, and how to avoid it by including both old and new FQDNs in the certificate.
When updating the NAT (Fully Qualified Domain Name) in Endpoint Central and importing a new certificate, agents may fail to communicate with the server, leading to a break in trusted communication.
Note: This case is only applicable when an Enterprise or third-party certificate is imported in the Endpoint Central server.
Endpoint Central enforces trusted communication between the server and agents, requiring certificate validation.
If a new certificate is imported containing only the new NAT FQDN, agents that still attempt to connect using the old NAT FQDN will face a Subject Alternative Name (SAN) mismatch. This mismatch causes certificate validation to fail, resulting in broken communication between the agents and the server.
To ensure a smooth and secure NAT FQDN update, follow these steps:
This process ensures that the agents can continue communication without validation errors during the transition period.