Traps ESM - whitelist signers

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Traps ESM - whitelist signers

Hello,

 

We have internal development team and we wnat them to use certificate to sign the exe file so we can then whitelist it in ESM. I have 3 questions related to it:

- "name of trusted signer" - is it CN field of Subject?

- how Traps will behave when certificate is no loger valid?

- how Traps will behave when certificate is revoked (granted CRL list is published and accessible)?

 

BTW there is an error in the documentation. Traps Management Service Admin page 23 - "To allow trusted signers previously seen in your environment, add the signer name (Windows) or SHA256 of the certificate that signs the file (macOS) to the Whitelist Signers list of the relevant Malware Security Profile." It should be SHA1 not SHA256. 

 

 

6 REPLIES 6

@Miroslaw_Iwanowski,

Correct. The Whitelisted Signer is simply looking at the CN, and if you know that "My Company" is how I sign my custom apps and send a targeted malware campaign with it signed as "My Company" and it's whitelisted in traps my malware will run the same as your custom app. 

So it is more like a vulnerability not a security feature. Shame.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!