Skip to main content

Overview

A shared secret is used to establish and maintain a trusted connection between Syteca and the Endpoint Risk & Compliance Control module. To maintain security and ensure uninterrupted operation, the secret should be rotated before it expires. During the rotation process, Endpoint Exposure Management supports both the old and the new secret until the previous secret reaches its expiration date, allowing administrators to update Endpoint Exposure Management without disrupting service.

Procedure

  1. In Syteca, locate the Auto-generated Endpoint Risk & Compliance Control application account (syteca_ercc) and open it for editing.
  2. Open the Endpoint Risk Control Portal in a new tab.
  3. In Syteca, add a new secret or rotate the existing one.
It is recommended, to always add a new secret and configure it in Endpoint Risk Control Portal before deleting/rotating the old one in Syteca.
  1. Copy the newly generated secret.
  2. Open the Endpoint Risk Control Portal.
  3. Navigate to Configuration.
  4. Locate the secret configuration field.
  5. Paste the newly generated secret into the masked secret field.
  6. Click Save.
  7. Confirm the action when prompted.
  8. Endpoint Risk & Compliance Control updates the stored secret and begins using it for communication with the Main Application.
  9. The rotation event is recorded in the internal audit log.
  10. Verify the Last Updated date displayed in the configuration page.
The secret must be rotated or updated before the current secret expires. Otherwise, Endpoint Risk Control Portal will become inaccessible.

What Happens After Rotation?

Once the new secret is saved:
  • Endpoint Risk & Compliance Control begins using the new secret for authentication.
  • The old secret remains valid until it expires.
  • Both secrets can be used during the transition period.
  • Communication between the Syteca and Endpoint Risk & Compliance Control module continues without interruption.
  • The rotation event is recorded for auditing purposes.

If the Secret Is Not Updated

If the secret expires before it is updated in Endpoint Risk & Compliance Control:
  • Authentication between the Syteca and Endpoint Risk & Compliance Control module will fail.
  • Users will no longer be able to access Endpoint Risk & Compliance Control through Syteca.
  • Administrative intervention will be required to restore connectivity.
In this situation, follow the troubleshooting procedures to restore the trusted connection. Troubleshooting:
  1. On the computer with the Syteca server, open a command prompt and navigate to the <Syteca Server Installation Folder>\ERCC directory.
  2. Run the following command: ercc_configtool tenant configure-parameter auth_client_secret
  3. When prompted, enter a new secret.

Key Considerations

  • Rotate secrets before their expiration date to avoid service interruptions.
  • Always verify that the new secret has been successfully saved in Endpoint Risk & Compliance Control.
  • The Last Updated field can be used to confirm when the current secret was configured.
  • Secret rotation events are automatically recorded in the internal audit log for traceability and compliance purposes.
  • During the grace period, both the previous and current secrets remain valid until the older secret expires.