
S W G U s e r G u i d e
Chapter 21: Implementing Cloud Security
132
Note that
Pending
status displays cloud users who will get certificates after you click
as opposed to
Non
issued
status, which displays cloud users who have not been issued a
certificate.
b. Click the
Filter
button.
This list of users, as filtered, is displayed below the filter row.
3. To manually issue a certificate to an uncertified user which makes the user a cloud user, click the
icon for the user and choose
Issue
New
Certificate
.
4. To manage the certificates of a particular user, click the
icon for the user and choose the
action to perform. Note the following points about possible actions:
•
Block
certificate
is a temporarily blocks, but does not revoke a certificate. It is intended for
use where a certificate is suspected of being compromised. If the certificate proves not to be
compromised, you can unblock it via the
Allow
certificate
option; if the certificate has been
compromised, you can permanently revoke it via the Revoke certificate option.
•
Revoke
certificate
is permanent; it cannot not be reversed. Instead a new certificate would
have to be issued via the
Issue
new
certificate
option, as described in
Step 3
.
• The
Send
provisioning
action re‐sends previously issued certificate information. This
option is useful if the initial certificate was lost.
• You can export a user’s certificate to an external file via the
Export
Certificate
option.
5. To export all certificates for all users who have valid certificates, click the
button at the bottom of the display.
Â
To enable automatic certification of all new users in a group, and to prevent
disabling of the Mobile Security Client
You can configure any User Group or LDAP Group so that all new users added to the group are auto‐
matically issued certificates. This is especially useful if you are dedicating the group to cloud users.
You can also ensure the users in the group cannot disable the Mobile Security Client agent on their
machines.
1. Display the list of user/LDAP groups as follows:
• For a regular user group, select
Users
Æ
Users/User
Groups
.
• For an LDAP group, select
Users
Æ
Authentication
Directories
Æ
LDAP
.
2. In the tree, select the group.
3. In the group definition screen, click
Edit
.
4. To ensure that each
new
user added to the group automatically becomes a cloud user, that is
issued a certificate, select the
Issue
Mobile
Security
Client
Certificates
to
new
group
members
checkbox. To issue certificates to all users who were in this group before you
performed this configuration, see
To manually issue or download certificates or emails at the
Group level
.
NOTE:
This
step
is
not
necessary
for
new
users
added
to
a
User
Group
or
LDAP
Group
that
automatically
ensures
issuance
of
certificates
to
new
users.
For
more
information,
see
To
enable automatic certification of all new users in a group, and to prevent disabling of the
Mobile Security Client
.
This
step
is
necessary,
however,
for
users
who
belonged
to
the
group
before
it
was
so
config
ured,
and
for
users
in
such
a
group
whose
certification
has
been
revoked.