12.07.2015 Views

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

McAfee Data Loss Prevention 9.2.2 Product Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using <strong>McAfee</strong> DLP DiscoverCrawling databases 4SSL certificate settingsSSL certificates identify the database server host and encrypt the data exchanged between databaseserver and the <strong>McAfee</strong> DLP device.<strong>Data</strong>bases must be set up to allow the <strong>McAfee</strong> DLP Discover client to connect using an SSL socket.All of the database types different configuration requirements for SSL, and if a certificate is required, itmust be exported from the server that is to be scanned. The services of a database administrator willbe needed to handle these tasks.<strong>McAfee</strong> DLP Discover client certificate handling is currently not supported.After the certificate is exported, it is imported into the TrustStore of the <strong>McAfee</strong> DLP Discoverappliance.Table 4-12 SSL certificate settings for database scansOptionNo SSL CertificateAny SSL certificateSigned SSL certificateDefinitionThe scanned data need not be encrypted.A certificate is required, but it can be non‐standard or self‐signed.The certificate must be verified by a legitimate authority.Add an SSL certificateIf a secure channel is needed for a database crawl, an SSL certificate might be used to encrypt trafficbetween the repository and the <strong>McAfee</strong> DLP Discover client.Before you beginIf a certificate is to be used, the <strong>Data</strong>base Administrator of the targeted repository mustfirst configure the database to use SSL for authentication and data exchange with clients.This involves exporting the public key of the SSL certificate to a file that the <strong>McAfee</strong> DLPadministrator will downloads for later upload to <strong>McAfee</strong> DLP Discover.DBAs should refer to the appropriate database user manual for details. The certificate mustbe PEM/X.509 standard, and in one of two formats: .cer (Base64 encoded) or .der(Windows encoded).This procedure explains only the SSL certificate portion of the creation of a database scan.When this part of the process is complete, the SSL certificate will have been uploaded tothe <strong>McAfee</strong> DLP Discover appliance.Task1 Select one of these options:• In ePolicy Orchestrator, select Menu | <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> | DLP Classify | Discover Scan Operations | SSLCertificates.• On your <strong>McAfee</strong> DLP appliance, select Classify | Discover Scan Operations | SSL Certificates.2 Create a database scan operation.3 Type in a name and optional description for the certificate.4 Browse to the location of the certificate on your desktop.Click the magnifying glass icon to get Certificate Details before you save it.If the certificate hasn't yet been exported from the repository to be scanned, contact the databaseadministrator.<strong>McAfee</strong> <strong>Data</strong> <strong>Loss</strong> <strong>Prevention</strong> <strong>9.2.2</strong> <strong>Product</strong> <strong>Guide</strong> 85

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!