background image

 

Integrated SSL Scanning

 

 

Page ii 

Copyright

 

© Copyright 1996-2008

. Finjan Software Inc. and its affiliates and subsidiaries (“Finjan”).  

All rights reserved. 

All text and figures included in this publication are the exclusive property of Finjan and 
are for your personal and non-commercial use. You may not modify, copy, distribute, 
transmit, display, perform, reproduce, publish, license, create derivative works from, 
transfer, use or sell any part of its content in any way without the express permission 
in writing from Finjan. Information in this document is subject to change without notice 
and does not present a commitment or representation on the part of Finjan.  

The Finjan technology and/or products and/or software described and/or referenced to 
in this material are protected by registered and/or pending patents including U.S. 
Patents No. 3952315, 6092194, 6154844, 6167520, 6480962, 6209103, 6298446, 
6353892, 6804780,

 

6922693, 6944822, 6993662, 6965968, 7058822, 7076469, 

7155743, 7155744 and may be protected by other U.S. Patents, foreign patents, or 
pending applications. 

Finjan, Finjan logo, Vital Security, Vulnerability Anti.dote and Window-of-Vulnerability 
are trademarks or registered trademarks of Finjan. Sophos is a registered trademark 
of Sophos plc. McAfee is a registered trademark of McAfee Inc. Kaspersky is a 
registered trademark of Kaspersky Lab. 

Websense® is a registered trademark of 

Websense, Inc. IBM® Proventia® Web Filter is a registered trademark of IBM 
Corporation.

 Microsoft and Microsoft Office are registered trademarks of Microsoft 

Corporation. All other trademarks are the trademarks of their respective owners. 

For additional information, please visit 

www.finjan.com

 or contact one of our regional 

offices: 

USA: San Jose  

2025 Gateway Place Suite 180 San Jose,  

CA 95110, USA  

Toll Free: 1 888 FINJAN 8  

Tel: +1 408 452 9700 Fax: +1 408 452 9701  

[email protected]  

Europe: UK 

4

th 

Floor, Westmead House, Westmead,  

Farnborough, GU14 7LP, UK

 

Tel: +44 (0)1252 511118  

Fax: +44 (0)1252 510888  

[email protected] 

 

Europe: Netherlands 

Printerweg 56 

3821 AD  Amersfoort, Netherlands 

Tel: +31 334 543 555 

Fax: +31 334 543 550 

[email protected] 

Europe: Germany 

Alte Landstrasse 27, 85521  

Ottobrun, Germany  

Tel: +49 (0)89 673 5970  

Fax: +49 (0)89 673 597 50 

[email protected]  

Israel/Asia Pacific 

Hamachshev St. 1,  

New Industrial Area Netanya, Israel 42504  

Tel: +972 (0)9 864 8200  

Fax: +972 (0)9 865 9441 

[email protected] 

 

Catalog name: ISC-FD-9.0-02 

Email: 

[email protected]

   

Internet: 

www.finjan.com

 

Содержание NG-5000

Страница 1: ...Software Version 9 0 Integrated SSL Scanning...

Страница 2: ...of Vulnerability are trademarks or registered trademarks of Finjan Sophos is a registered trademark of Sophos plc McAfee is a registered trademark of McAfee Inc Kaspersky is a registered trademark of...

Страница 3: ...ts 1 Introduction 1 2 HTTPS Scanning 1 2 1 On the Fly Certificate Generation 1 2 2 Certificate Validation 2 2 3 SSL Certificate Errors 6 3 HTTPS Policies 11 4 Configuring HTTPS Support 11 4 1 HTTPS Co...

Страница 4: ...injan also provides certificate validation functionality This ensures that corporate policies regarding certificates are enforced by automatically validating each certificate and ensuring that the cha...

Страница 5: ...ital certificate lists are updated via Finjan security updates These lists include the required trusted certificate authorities as well as the Certificate Revocation Lists CRLs Certificate validation...

Страница 6: ...means that the actual signature value could not be determined rather than it not matching the expected value CRL signature failure The signature of the certificate is invalid Certificate is not yet v...

Страница 7: ...Structure Field Description Certificate signature cannot be decrypted The certificate signature could not be decrypted meaningful for RSA keys Cannot decode issuer public key The public key in the cer...

Страница 8: ...rusted for the specified purpose Certificate rejected The root CA is marked to reject the specified purpose Subject issuer mismatch The current candidate issuer certificate was rejected because its su...

Страница 9: ...e is before the current time 2 3 SSL Certificate Errors When the end user opens the HTTPS session the Scanning Server has to encrypt and decrypt the data between the end user and the Scanning Server T...

Страница 10: ...ervers issued by the organization s CA root certificate which is already trusted by all users NOTE Using a certificate from a trusted CA such as VeriSign will not prevent the certificate validation ch...

Страница 11: ...KiCKy JqpuLU0MuXsOOQ END CERTIFICATE 2 Install the certificate on the browser To install the certificate on Internet Explorer a In the control panel click Internet Options b Click the Content tab and...

Страница 12: ...Copy this into a separate text file to send to a certificate authority 6 Once you have a certificate back send it to your end users to install on their browsers 7 In the Limited Shell enter the comma...

Страница 13: ...dy configured to trust the organizations root CA and there is no need to configure anything for the users To install the root certificate on the Scanning Server 1 Connect to the Management Console via...

Страница 14: ...In addition to the above two policies the user can configure additional policies and rules The security policies apply only to the way that the scanning server handles the certificate validation bypas...

Страница 15: ...is disabled by default This protocol is non secure and should not be used unless there are compatibility problems Allow SSLv3 Enables support for SSLv3 protocol This option is enabled by default Allow...

Страница 16: ...is timed out if not responsive Max HTTPS Transactions Backlog Defines the maximum number of outstanding connection requests to be served by the system After this number is reached the system is timed...

Страница 17: ...to configure proxy settings for the users This can be done by using one of the following methods Layer 4 Switch By using a third party layer 4 switch it is possible to redirect all traffic destined to...

Страница 18: ...still mandatory to install the SSL certificate of the Scanning Server on the end user s PC in order to prevent the security warnings When the end user browses an HTTPS site the Scanning Server generat...

Отзывы: