01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Modules for SSL scanning<br />

<strong>Web</strong> filtering<br />

SSL scanning 6<br />

The SSL scanning rules call several modules to execute jobs that are related to SSL scanning. This<br />

section tells you how to configure these modules.<br />

You can configure the following modules:<br />

• SSL Scanner — Enables certificate verification and content inspection, which are key jobs in SSL<br />

scanning.<br />

Typically, there are separate settings for the module when called to verify certificates and when<br />

called to inspect content.<br />

• SSL Client Context — Handles the sending of a certificate from the appliance to a client.<br />

After the initial setup, the module uses a certificate issued by the default root certificate authority<br />

(CA) that is implemented on the appliance. For further administration, it is recommended that you<br />

create your own root CA, using the options provided with the module settings.<br />

• Certificate Chain — Handles the building of a certificate chain.<br />

When building the chain, the module uses a list of certificate authorities for the certificates that are<br />

included in the chain. You can add certificate authorities to existing lists and also add new lists.<br />

Configure a module for SSL scanning<br />

This section describes the procedure for configuring the modules that are involved in SSL scanning.<br />

To configure an SSL scanning module:<br />

1 Go to Policy | Settings.<br />

2 On the Engines branch of the settings tree, go to the module you want to configure settings for and<br />

select these settings. For example, go to SSL Scanner and select Default Certificate Verification.<br />

3 Configure these settings as needed.<br />

4 Click Save Changes.<br />

For more information on these settings, see SSL Scanner engine settings, SSL Client Context engine<br />

settings, and Certificate Chain engine settings.<br />

SSL Scanner engine settings<br />

You can configure the SSL Scanner engine settings. These are the settings for the module that the SSL<br />

scanning rules call to verify certificates and enable content inspection in SSL-secured communication.<br />

Note: These settings can be configured on the Settings tab of the Policy top-level menu.<br />

Certificate Verification Without EDH<br />

Settings for the SSL Scanner module when it uses a special mode to verify certificates in<br />

communication with web servers that do not support the EDH (Ephemeral Diffie-Hellman) method<br />

Meaning and usage of these settings are the same as for the Default Certificate Verification settings.<br />

For the Server cipher list parameter, the string specified as its value usually differs from the string<br />

specified for the default settings.<br />

For more information, see Default Certificate Verification.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 223

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!