12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing <strong>McAfee</strong> DLP systemsAdding servers to <strong>McAfee</strong> DLP systems 136 Select one or more groups from the Available groups for the new user and Add the users to thegroups.7 Click Apply.To make changes to the user's status later, click Details for the user's account.For example, you can use the Action menu to Disable or Delete the user.Export certificates from Active Directory serversExport certificates from Active Directory servers to secure the connection to <strong>McAfee</strong> DLP Manager.This task retrieves a certificate from a Microsoft Active Directory server, exports it, and adds it in the<strong>McAfee</strong> DLP Manager interface.By default, LDAP traffic is transmitted unsecured, but using secure LDAP over SSL technology encryptsthe connection.Task1 Log on as a member of one of the following:• The local Administrator security group for standalone computers• A member of the Domain Administrator security group for any computers that are connected tothe domain.2 Install the certificate on the Windows server, which will install the server certificate on the ActiveDirectory server.3 Start the Microsoft Management Console by clicking Start | Programs | Administrative Tools | CertificateAuthority.4 Select the CA system, then right‐click and select Properties.5 From the General menu, select View Certificate.6 Select the Details view.7 Click Copy to File on the lower right corner of the window.8 Use the Certificate Export Wizard to save the CA certificate in one of the following formats:• DER Encoded Binary X‐509 format• Base‐64 Encoded X‐509 format9 Verify that SSL is enabled on the Active Directory server:• Windows 2000• Windows 2003abcEnsure that Windows 2000 Support Tools (Windows Support Tools on Microsoft Windows 2003) is installedon the Active Directory server.Find the suptools.msi setup program in the \Support\Tools\ directory on your Windows CD.Start the ldp tool.For Microsoft Windows 2000 systems, select Start | Windows 2000 Support Tools | Tools | Active DirectoryAdministration Tool. For Windows 2003, select Start | Windows Support Tools | Tools | Command Prompt.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 265

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!