HTTP Server Setup for McAfee Endpoint Encryption (Formerly SafeBoot) Table of Contents



Similar documents
Wavecrest Certificate

How to Configure a Secure Connection to Microsoft SQL Server

Install the Production Treasury Root Certificate (Vista / Win 7)

Outlook Web Access Guide to Installing Root Certificates, Generating CSR and Installing SSL Certificate

Setting Up SSL on IIS6 for MEGA Advisor

HTTP communication between Symantec Enterprise Vault and Clearwell E- Discovery

SETUP SSL IN SHAREPOINT 2013 (USING SELF-SIGNED CERTIFICATE)

Sophos Anti-Virus for NetApp Storage Systems startup guide

NSi Mobile Installation Guide. Version 6.2

etoken Enterprise For: SSL SSL with etoken

ADFS Integration Guidelines

ECA IIS Instructions. January 2005

Microsoft Exchange 2010 and 2007

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

Enable SSL for Apollo 2015

Direct Storage Access Using NetApp SnapDrive. Installation & Administration Guide

2. In the Search programs and files field, enter mmc and hit the enter key

DMZ Server monitoring with

WECCNET MESSAGING SYSTEM CLIENT DOCUMENTATION

Sophos Anti-Virus for NetApp Storage Systems startup guide. Runs on Windows 2000 and later

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

SSL Intercept Mode. Certificate Installation Guide. Revision Warning and Disclaimer

Aspera Connect User Guide

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

Chapter 2 Editor s Note:

Sophos Anti-Virus for NetApp Storage Systems user guide. Product version: 3.0

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

How to set up Outlook Anywhere on your home system

SQL Server 2008 and SSL Secure Connection

INSTALLING YOUR SSL CERTIFICATE ON THE FILEHOLD SERVER ON WINDOWS 2008 X64 ON IIS 7

MultiSite Manager. Using HTTPS and SSL Certificates

Step-by-Step Setup Guide Wireless File Transmitter FTP Mode

How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip

RSA Security Analytics

e-cert (Server) User Guide For Microsoft IIS 7.0

EM L12 Symantec Mobile Management and Managed PKI Hands-On Lab

Set Up Setup with Microsoft Outlook 2007 using POP3

Smart Policy - Web Collector. Version 1.1

DIGIPASS Authentication for Microsoft ISA 2006 Single Sign-On for Outlook Web Access

MicrosoftDynam ics GP TenantServices Installation and Adm inistration Guide

MadCap Software. Upgrading Guide. Pulse

LAB 1: Installing Active Directory Federation Services

Browser-based Support Console

Shellfire L2TP-IPSec Setup Windows XP

4cast Client Specification and Installation

S/MIME on Good for Enterprise MS Online Certificate Status Protocol. Installation and Configuration Notes. Updated: October 08, 2014

Outlook Profile Setup Guide Exchange 2010 Quick Start and Detailed Instructions

LifeSize Control Installation Guide

Microsoft IIS 7 Guide to Installing Root Certificates, Generating CSR and Installing certificate

Installation and Configuration Guide

Generating an Apple Push Notification Service Certificate for use with GO!Enterprise MDM. This guide provides information on...

Installing Globodox Web Client on Windows 7 (64 bit)

QUANTIFY INSTALLATION GUIDE

Important Notes for WinConnect Server VS Software Installation:

Distributing SMS v2.0

How to use mobilecho with Microsoft Forefront Threat Management Gateway (TMG)

Step-by-step installation guide for monitoring untrusted servers using Operations Manager ( Part 3 of 3)

Exchange Outlook Profile/POP/IMAP/SMTP Setup Guide

Managing Contacts in Outlook

BASIC CLASSWEB.LINK INSTALLATION MANUAL

Copyright

client configuration guide. Business

Secure IIS Web Server with SSL

Desktop Surveillance Help

APNS Certificate generating and installation

Generating a Certificate Signing Request (CSR) from LoadMaster

DX8100 Series Symantec AntiVirus Corporate Edition Installation Instructions. Version

eadvantage Certificate Enrollment Procedures

Changing Your Cameleon Server IP

ESET SECURE AUTHENTICATION. API SSL Certificate Replacement

USING SSL/TLS WITH TERMINAL EMULATION

Windows Server 2003 x64 with Symantec AntiVirus 10 Corporate Edition

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

Configuring Outlook for Windows to use your Exchange

Setup SSL in SharePoint 2013 Using Domain Certificate

Mobility Manager 9.0. Installation Guide

Reference and Troubleshooting: FTP, IIS, and Firewall Information

Installation instructions for the supplier VPN solution

Parallels Mac Management for Microsoft SCCM 2012

How schedule AccuTRConsole to run every hour

Configuring Load Balancing

RoomWizard Synchronization Software Manual Installation Instructions

SCCM Client Checklist for Windows 7

Ekran System Help File

CA NetQoS Performance Center

Connection and Printer Setup Guide

Accessing the Media General SSL VPN

Account Create for Outlook Express

DriveLock Quick Start Guide

Step-by-Step Guide for Creating and Testing Connection Manager Profiles in a Test Lab

Quadro Configuration Console User's Guide. Table of Contents. Table of Contents

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

Step-by-Step Guide for Setting Up VPN-based Remote Access in a

Verify LDAP over SSL/TLS (LDAPS) and CA Certificate Using Ldp.exe

Disabling Microsoft SharePoint in order to install the OneDrive for Business Client

Windows XP with Symantec AntiVirus 10 Corporate Edition

Using TLS Encryption with Microsoft Outlook 2007

Installation Instruction STATISTICA Enterprise Server

TAMUS Terminal Server Setup BPP SQL/Alva

OPC Unified Architecture - Connectivity Guide

Transcription:

Table of Contents Introduction... 1 Setting Up Endpoint Encryption s HTTP Server...2 How to trust Control Break as an CA... 20 Start Endpoint Encryption s HTTP Server service... 23 Verify Endpoint Encryption HTTP Server Status on the Server... 26 Introduction This document describes how to set up the Endpoint Encryption HTTP server and install the Northwestern Mutual Certificate. This operation must be completed to allow use of Endpoint Encryption s webhelpdesk and webrecovery tools from this server. In addition, a Firewall Change Request must be submitted, approved, and implemented before setting up Endpoint Encryption s HTTP server to allow HTTPS communication to and from the server through port 449. This operation can only be performed directly on the server that hosts the Endpoint Encryption Administration database. Use Remotely Anywhere (RA) to access the server and execute the tasks below during an RA session. NOTE: Throughout this document as well as the McAfee Endpoint Encryption product, there are references to SafeBoot in the User Interface. It must be understood that wherever SafeBoot exists, it refers to the McAfee Endpoint Encryption product. McAfee, Inc. Page 1 of 27

Setting Up Endpoint Encryption s HTTP Server NOTE: It is assumed that the Northwestern Mutual Certificate is located in c:\temp. 1. From within an RA session, open the Start menu and select Run. Type MMC.EXE in the Open: dropdown box of the Run screen and click OK. This opens the Microsoft Management Console screen displayed below. McAfee, Inc. Page 2 of 27

2. Navigate to the Console menu and select the Add/Remove Snap-In menu option as shown below. This action opens the Add/Remove Snap-In screen, displayed behind the active window in the screen print below. Click on the Add button in the Add/Remove Snap-In screen. This opens the Add Standalone Snap-In screen displayed in the active window below. McAfee, Inc. Page 3 of 27

3. In the Add Standalone Snap-In screen, either double-click the Certificates list item or select the Certificates list item and click the Add button to open the Certificates Snap-In screen displayed below. Choose the Services Account option in the Certificates Snap-In screen. Click the Next button to continue. McAfee, Inc. Page 4 of 27

4. In the Select Computer screen, choose the Local Computer option as shown below and click the Next button to continue. 5. In the Certificates Snap-In screen, select SafeBoot HTTP Server and click the Finish button. McAfee, Inc. Page 5 of 27

6. The previous action closes the Certificates Snap-In screen and returns to the Add Standalone Snap- In screen shown below. Close the Add Standalone Snap-In screen by clicking the Close button, hidden below by the Remotely Anywhere notification window. McAfee, Inc. Page 6 of 27

7. Closing the Add Standalone Snap-In screen returns to the Add/Remove Snap-In screen below. Click the OK button to return to the Microsoft Management Console screen. McAfee, Inc. Page 7 of 27

8. In the Microsoft Management Console screen, expand the Certificates entry under the Console Root folder. McAfee, Inc. Page 8 of 27

9. Select the SafeBootHttpServer\Personal entry, then right-click to view the shortcut menu. Choose the All Tasks shortcut menu option, then Import as displayed below to begin to import the HTTP server s SSL certificate. McAfee, Inc. Page 9 of 27

10. Click Next at the first screen of the Certificate Import Wizard to initiate the import of the SSL certificate. McAfee, Inc. Page 10 of 27

11. Click on the Browse button in the second screen of the Certificate Import Wizard to present the Open window used to locate the SSL certificate. This file will be in c:\temp named after the server name: ServerName.yourdomain.com Note: The temporary certificate is in \Tools\HTTP Certificates folder of the SafeBootCD McAfee, Inc. Page 11 of 27

12. After locating and selecting the SSL certificate and returning to the Certificate Import Wizard window as shown below, click Next to continue through the wizard. McAfee, Inc. Page 12 of 27

13. Enter 12345 in the Password: as shown below, and click Next to continue through the wizard. 14. Accept the default Certificate Store option as shown below ( Place all certificates in the following store: SafeBootHTTPServer\Personal) and click Next to continue through the wizard. McAfee, Inc. Page 13 of 27

15. Review the options displayed in the final screen of the Certificate Import Wizard. Click Finish to import the SSL certificate. McAfee, Inc. Page 14 of 27

16. The Certificate Import Wizard presents a confirmation dialog box if the import was successful. This confirmation is shown below. McAfee, Inc. Page 15 of 27

17. Select Certificates as shown below to display the imported SSL certificate in the right-hand pane. McAfee, Inc. Page 16 of 27

18. Save the MMC console just created. Select the Console menu, then the Save As option. McAfee, Inc. Page 17 of 27

19. Name the newly-created console Webrecovery, and click the Save button to save the console. McAfee, Inc. Page 18 of 27

20. Next edit the following files: d:\sbadmin\sbhttp.ini d:\sbadmin\sbhttpadmin.ini Change Server.Ssl.Certname=127.0.0.1 into Server.Ssl.Certname=ntapsh0799m00.test.nmfco.com 21. Stop the SafeBoot HTTP server under services McAfee, Inc. Page 19 of 27

How to trust Control Break as an CA Start internet Explorer. Fill in https://servername.yourdomain.com and press Enter. HTTP Server Setup for McAfee Endpoint Encryption The screen above will appear. Choose View Certificate The screen above will appear. McAfee, Inc. Page 20 of 27

Choose Install Certificate The screen above will appear. Press next and select Place all certificates in the following store The screen above will appear. Browse to Trusted Root Certification Authorities McAfee, Inc. Page 21 of 27

The screen above will appear. Press OK, Next, Finish, Yes OK NOTE: This action should be performed on every PC that will use this tool. Otherwise you will get a warning, every time you start the Webserver. McAfee, Inc. Page 22 of 27

Start Endpoint Encryption s HTTP Server service 1. Open the Services applet (START->PROGRAMS->Administrative Tools->Services) on the server. Select Settings Control Panel Administrative Tools Services McAfee, Inc. Page 23 of 27

2. Select the SafeBoot HTTP Server item in the Services list and right-click the item. Select the Start shortcut menu option to start the service. McAfee, Inc. Page 24 of 27

3. The SafeBoot HTTP Server should now show a status of Running as shown below. McAfee, Inc. Page 25 of 27

Verify Endpoint Encryption HTTP Server Status on the Server 1. Open Internet Explorer on the server. Enter the following URL to test that the Endpoint Encryption HTTP Server is operational: https://servername.yourdomain.com. Press enter to attempt to connect to the HTTP server. You may see a message as shown in the foreground below. McAfee, Inc. Page 26 of 27

2. The dialog box shown in the foreground below appears when the browser connects with a URL that has an SSL certificate associated with it. Click Yes to proceed. If you get this warning you still have to trust the SafeBoot CA as mentioned in this document already. 3. The SafeBoot Web Helpdesk application will appear in the browser if the HTTP server is operational. McAfee, Inc. Page 27 of 27