Installation with Custom TLS and with Peer Verification
This installation type installs the following Tenable Identity Exposure components with custom TLS and peer verification.
Public Key Infrastructure (PKI) Certificate
To use peer verification, your PKI certificate must include the IP addresses or DNS of all the machines used to install Tenable Identity Exposure.
Order of installation
Install the components in the following order:

-
On the local machine, run the installation file Tenable.ad_v3.29.x.exe.
A welcome screen appears.
-
In the setup language box, click the arrow to select the language for the installation, and click Next.
The Setup Wizard appears.
-
Select the Expert Mode checkbox.
-
Click Next.
The Custom Setup window appears.
-
Deselect the Security Engine Nodes and Directory Listener components.
-
Click Next.
The TLS Options window appears.
-
Select the TLS with custom certificates with peer validation option.
-
Click Next.
The TLS certificates window appears.
-
Provide the following information:
-
Click Next.
The Storage Manager window appears.
-
In the Password box, type a password for the MSSQL database.
Note: The installer requires an SA password with the syntax described in Strong Passwords for the SQL Server.
Note: Tenable strongly recommends that you keep the default TENABLE instance name.
-
Click Next.
The Ready to Install window appears.

-
On the local machine, run the installation file Tenable.ad_v3.29.x.exe.
A welcome screen appears.
-
In the setup language box, click the arrow to select the language for the installation, and click Next.
The Setup Wizard appears.
-
Select the Expert Mode checkbox.
-
Click Next.
The Custom Setup window appears.
-
Deselect the Storage Manager and Directory Listener components.
Note: To install SEN services over several machines, see Split Security Engine Node (SEN) Services.
-
Click Next.
The TLS Options window appears.
-
Select the TLS with custom certificates with peer validation option.
-
Click Next.
The TLS certificates window appears.
-
Provide the following information:
-
In the Server PFX Archive box, click ... to browse to your PFX archive.
-
In the PFX Password box, type the password for the PFX file.
-
In the CA Cert File box, click ... to browse to your CA certificate file.
-
-
Click Next.
The Storage Manager window appears.
-
Provide the following information:
-
In the MSSQL box, type the IP address of the Storage Manager.
-
In the Password box, type the service account password for the MSSQL database defined in the Storage Manager installation.
Note: The installer requires an SA password with the syntax described in Strong Passwords for the SQL Server.
-
-
Click Next.
The Security Engine Node window appears.
-
In the DNS name or IP box, type the DNS name (preferred) or IP address of the web server that end users enter to access Tenable.ad.
Note: By default, the installation process creates a self-signed certificate with the DNS name or the IP address that you entered. For more information, see Change the IIS Certificate.
-
Click Next.
The Ready to Install window appears.

-
On the local machine, run the installation file Tenable.ad_v3.29.x.exe.
A welcome screen appears.
-
In the setup language box, click the arrow to select the language for the installation, and click Next.
The Setup Wizard appears.
-
Select the Expert Mode checkbox.
-
Click Next.
The Custom Setup window appears.
-
Deselect the Storage Manager and the Security Engine Nodes components.
-
Click Next.
The TLS Options window appears.
-
Select the TLS with custom certificates with peer validation option.
-
Click Next.
The TLS certificates window appears.
-
In the CA Cert File box, click ... to browse to your CA certificate file.
-
Click Next.
-
The Security Engine Node window appears.
-
In the IP box for RabbitMQ, type the address of the Security Engine Node hosting RabbitMQ.
-
Click Next.
The Directory Listener window appears.
-
In the Subnets box, type the subnet address for the Directory Listener. For multiple subnets, use a comma to separate the addresses.
-
Click Next.
The Ready to Install window appears.
-
Click Install to begin the installation.
After the installation completes, the Completing the Tenable.ad Setup Wizard window appears.
-
Click Finish.
A dialog box asks you to restart your machine.
-
Click Yes.
The machine restarts.
-
Restart the SEN machine.
-
Restart the Storage Manager machine.