Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Bastion should have a configuration for supporting certification on it's HTTPS listener

Client set-up

Windows: /wiki/spaces/SKYP/pages/625246999Configuring Outlook 2016 - Certificate Based Auth

MAC: Configuring Certificate Based Auth in MACMAC with client certificate for Exchange


CAF Filter High-level functionality :

...

  1. Verify that the device is managed by MDM
  2. Verify the compliance level of Device
  3. Register the device on SphereShield for getting visibility on all devices connecting externally to Exchange
  4. Verify that certificate is issued by root certificate as configured by MDM vendor 
  5. Validate certificate values based on regex engine
  6. Configurable mapping of certificate attributes to extract user and device info from certificate
  7. Update last saw time and the last IP used of a device
  8. Write into security auditing all events
  9. Enable validation/inserting data based on specific CN out of the subject/issuer 

Topology:

Image Added