The following new features and enhancements are contained in the 4.9.0 version of the
This version includes an update to the HTTPS processing layer, resulting in enhanced HTTPS interception capability.
Administration user permissions are now defined in a role rather than as part of a user account, and Active Directory groups can be linked to
When uploading a Certificate Authority (CA) certificateA digital means of proving your identity. When you send a digitally-signed message, you are sending your certificate and public key. Certificates are issued by a certification authority and can expire or be revoked., validation checks are performed on the certificate and credentials. If a CA certificate is found to be invalid, error or warning messages are displayed for guidance, detailing the reason the validation failed. If you receive warnings on your CA certificate upload, you can proceed with the upload if you wish. However, if you receive error messages, the errors must be resolved before you can continue. Potential reasons for failed validation include:
Errors
Warnings
See Uploading a Certificate Authority certificate for more information.
You can now select Avira anti-virus, alongside Sophos and/or Kaspersky. See Anti-Virus Scanners for more information.
All HTTPS event logging has been consolidated into the Decryption Service log. The HTTPS CA Server log, which is now redundant, has been removed.
See Logs for more information.
Verification of HTTPS certificates has been improved and simplified to conform to up-to-date security standards. You can configure the Gateway to block access to sites using expired, invalid, or untrusted certificates. Matching of the certificates against the site hostname has been enhanced to conform to current Internet standards. Specifically, name matching is performed against the Subject Alternative Name (SAN) in preference to the Common Name (CN) of a certificate. See HTTPS Certificate Verification for more information.
The Web Gateway dynamically generates a certificate for connecting clients. A certificate is generated for each site visited. Before a certificate is generated, the Web Gateway checks the cache to ensure that a certificate has not been already generated for this site. You can set the maximum number of cached certificates, which defaults to 100,000. The cache contents are reset at midnight daily and can also be manually reset.
See Certificate caching for more information.
The system now proactively checks for revoked intermediate Certificate Authority certificates. The service refreshes the revocation list periodically and if the list download fails more than 5 times in a row, the Downloading certificate revocation list failed too many times alarm is raised. See System Alarms for more information.
The Detect Lexical Expression content rule now supports Microsoft Project (MPP) files as a media type in the What to Look For? panel.
Enabling the Infrastructure information check box, in the What to Look For? panel of the Sanitize Document Content rule, configures the
You can now configure the
© 1995–2018 Clearswift Ltd.