![Sophos SM2000 Скачать руководство пользователя страница 144](http://html.mh-extra.com/html/sophos/sm2000/sm2000_user-manual_1332507144.webp)
4.4.11 Certificates
Use the Configuration > System > Certificates page to manage the
used by the
appliance. This certificate is used by the Web Appliance to create secure connections with browsers
for HTTPS scanning as well as the Administrative User Interface.
Note: You can either provide your own certificate, or use the self-signed certificate provided with
the Web Appliance.
On the Certificate Authority tab you can select from the following:
■
Original Sophos Certificate The original self-signed certificate provided with the appliance
will expire soon. When it expires, the appliance will automatically switch to the new certificate.
To prevent end-user warnings, download the new Sophos certificate using the link provided
and deploy it to all users. Then, select New Sophos Certificate.
■
Sophos Certificate This option replaces the original Sophos certificate and is available only
after you have switched to the new Sophos certificate.
■
Custom Certificate Use your own private key and signing certificate.
Note: In the near future, Microsoft, Mozilla, and potentially other companies will begin to block
or warn when using SHA-1 based certificates. You can use the new Regenerate Certificates
button to switch the Sophos certificate to a more secure SHA-256 signature.
Related reference
Certificates and Certificate Authorities
4.4.11.1 Custom Certificate
When you select Custom Certificate, controls will be displayed that allow you to upload a private
key and a custom certificate.
■
To add a custom certificate:
■
For the Private key, click the Choose file button, and select the file that contains the private
key associated with the custom certificate that you want to use.
■
For the Signing certificate, click the Choose file button, and select the file that contains
the custom certificate that you want to use.
■
Click Upload to add the private key and signing certificate pair that you want to use.
Note: The certificate must be in PEM or PKCS#12 format. A certificate must be a self-signed
certificate that has been deployed to endpoint browsers, or by one of the authorities already
supported by the browser on the endpoint.
Related reference
Certificates and Certificate Authorities
4.4.12 Endpoint Web Control
If you want to use an appliance together with Sophos Enterprise Console, you must provide
Enterprise Console with an appliance hostname and an authentication key. Once this is configured,
a web control policy can be applied to the endpoint machines by the designated appliance.
144 | Configuration | Sophos Web Appliance