01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6<br />

<strong>Web</strong> filtering<br />

SSL scanning<br />

Certificate Verification<br />

This nested rule set handles the CERTVERIFY call in SSL-secured communication. It lets whitelisted<br />

certificates skip verification and blocks others according to particular criteria.<br />

Nested library rule set — Certificate Verification<br />

Criteria — Command.Name equals “CERTVERIFY”<br />

Cycle — Requests (and IM)<br />

The rule criteria specifies that the rule set applies if a request is received on the appliance that contains<br />

the CERTVERIFY command, which is sent to request the verification of a certificate.<br />

The rule set contains the following rules:<br />

Skip verification for certificates found in Certificate Whitelist<br />

SSL.Server.Certificate.HostAndCertificate is in list Certificate Whitelist –> Stop Rule Set<br />

The rule lets whitelisted certificates skip verification.<br />

Block self-signed certificates<br />

SSL.Server.Certificate.SelfSigned equals true –> Block <br />

The rule blocks requests with self-signed certificates. The action settings specify a message to the<br />

requesting user.<br />

Block expired server (7 day tolerance) and expired CA certificates<br />

SSL.Server.Certificate.DaysExpired greater than 7 OR<br />

SSL.Server.CertificateChain.ContainsExpiredCA equals true –> Block <br />

The rule blocks requests with expired server and CA certificates. The action settings specify a<br />

message to the requesting user.<br />

Block too long certificate chains<br />

SSL.Server.CertificateChain.PathLengthExceeded equals true –> Block <br />

The rule blocks a certificate chain if it exceeds the path length.<br />

The settings in the property specify a list for the module that checks the certificate authorities. The<br />

action settings specify a message to the requesting user.<br />

Block revoked certificates<br />

SSL.Server.CertificateChain.ContainsRevoked equals true –> Block <br />

The rule blocks a certificate chain if one of the included certificates has been revoked.<br />

The settings in the property specify a list for the module that checks the certificate authorities. The<br />

action settings specify a message to the requesting user.<br />

Block unknown certificate authorities<br />

SSL.Server.CertificateChain.FoundKnownCA equals false –> Block <br />

The rule blocks a certificate chain if none of the certificate authoritiies (CAs) issuing the included<br />

certificates is a known CA . The settings in the property specify a list for the module that checks<br />

the certificate authorities.<br />

The action settings specify a message to the requesting user.<br />

218 <strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!