01.01.2013 Views

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

Web Gateway 7.1.5 Product Guide - McAfee

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

8 Click OK. The window closes and the certificate authority is imported.<br />

9 Click Save Changes.<br />

<strong>Web</strong> filtering<br />

SSL scanning 6<br />

The certificate authority you imported through this procedure is the one that is used for issuing the<br />

certificate the appliance sends to its clients in the starting phase of the SSL-secured communication.<br />

For information on other settings for the communication between the appliance and its clients, see SSL<br />

Client Context engine settings.<br />

Certificate Chain engine settings<br />

You can configure the Certificate Chain engine settings. These are the settings for the module that<br />

deals with the certificates the appliance receives from web servers.<br />

Note: These settings can be configured on the Settings tab of the Policy top-level menu.<br />

Default<br />

Default settings for the Certificate Chain module<br />

Certificate Verification<br />

Settings for the certificates used to build a certificate chain<br />

List of certificate authorities — List for selecting a list of certificate authorities (CAs) that sign the<br />

certificates in a certificate chain<br />

The following table describes the entries in a list of certificate authorities. For information on<br />

maintaining a list of this type, see Inline lists.<br />

Table 6-21 List of certificate authorities lists<br />

Option Definition<br />

Certificate authority Name of a certificate authority<br />

Certificate revocation list List with information on when a certificate signed by this certificate authority<br />

becomes invalid and the URI used to access the list<br />

Trusted Information on whether a certificate authority is trusted on the appliance<br />

Comment Plain-text comment on a certificate authority<br />

For information on how to import a certificate authority for the certificates in a certificate chain, see<br />

Add a certificate authority.<br />

Add a certificate authority<br />

This section describes a procedure for importing an existing certificate authority (CA) and adding it to a<br />

list of known certificate authorities.<br />

To import and add a certificate authority:<br />

1 Go to Policy | Settings.<br />

2 On the Engines branch of the settings tree, go to Certificate Chain and select the settings you want<br />

to configure, for example, Default.<br />

3 Select a list of certificate authorities and click Edit. The Edit List (Certificate Authority) window opens.<br />

4 Click Add. The Add Certificate Authority window opens.<br />

5 [Optional] Type the name of a certificate revocation list (CRL) in the input field provided here and<br />

select or deselect Trusted, according to the status the new certificate authority should have.<br />

6 Click Import. A window opens to let you access your file system.<br />

7 Browse to the file for the certificate authority you want to import and click Open. The window closes<br />

and information on the new certificate authority appears in the Add Certificate Authority window.<br />

<strong>McAfee</strong> <strong>Web</strong> <strong>Gateway</strong> <strong>7.1.5</strong> <strong>Product</strong> <strong>Guide</strong> 227

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!