Hi, BigFix uses Self-signed SSL certificates generated from their own trust chain for the server and relays, rather than certificates that are rooted in a common certificate authority. BigFix communications between the BigFix Root Server and the BigFix Clients /Relays are already secured.
Please, refer to following knowledge article:
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0022559
Regards,
#AIX
#Support#SupportMigration