SANGFOR IAM v2.1 User Manual
135
[Enable SSL Control]: Check this item to enable the [SSL black/white list control] function.
Type the black list and white list respectively in the corresponding text box; and configure
whether to enable the expired certificate.
[Deny certificates issued by the following organizations]: Defines the certificate issuer of the
website which is denied to be accessed. This is what is called as the “Black List”.
[Only allow certificates issued by the following organizations]: Defines the certificate issuer of the
website which is allowed to be accessed. This is what is called as the “White list”.
[Deny expired certificate]: Check this item and it will verify whether the certificate has expired. If
it has expired, the LAN user then cannot access this website.
[Enable SSL certificate chain control] is used for verifying the certificate chain according to the
trusted root certificates listed in [Object] > [SSL certificate] page. If the sub CA is not coherent to
the root CA, or the certificate has been altered during the issuing process, the LAN computer will
be denied to get access to the Internet.
7.1.2.4.2.
SSL Content Ident
[SSL Content Ident] can identify the SSL-encrypted WEBMAIL, WEB-BBS, POP3 and SMTP
contents (financial services such as online banking and online payment are excluded).