In order to satisfy security scanner software the CA certificate used by Protector for inter-node communications needs to be trusted by the tool. To do this:
- Create a copy of <installdir>/db/ssl/certificates/cacert.pem
- Rename it to cacert.crt
- Propagate cacert.crt to all the relevant machines via your preferred method. This varies by OS and by configuration so is not documented here.