This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

As of August 8th 2023, SSL/TLS Decryption is enabled in the EAP program for macOS devices.

Sophos,


Considering the impact that this new feature contains, it could have been better handled to send notification of this new feature at least a day before it happens, as opposed to sending the notification on the same day this new feature is enabled!

MacOS Endpoint EAP - August 2023 Update 

(https://community.sophos.com/intercept-x-endpoint/macos-endpoint-eap/b/announcements/posts/macos-endpoint-eap--august-2023-update)

From a macOS deployment perspective, the following challenges exist:

  1. A reboot is needed (minor challenge)
  2. End user must allow a Sophos Trusted Certificate (bigger challenge).
  3. End user must navigate within Sophos Endpoint application, click a button, and enter their password to authorize the certificate (bigger challenge).
  4. The Sophos KB is vague whether “enter password” is for end-user’s password or needing administrative credentials, though since the password is needed to “authorize the certificate”, it is reasonable to assume the latter (so, even bigger challenge).
  5. Steps 2-4 are all manual; Sophos does not provide any method whether these steps can be done using MDM or other automatic means (biggest challenge)


This thread was automatically locked due to age.
Parents
  • Agree with all the points above. There needs to be an MDM method to alleviate all of these deployment steps. Also, we don't have SSL inspection turned on in our environment, yet the clients were still asked to do the steps above. If SSL inspection isn't turned on in the console, then we shouldn't be required to make any changes.

  • As this is an EAP, the control in Central that enables SSL decryption is located under Settings, in the HTTPS/SSL decryption global settings section. There is a check mark there for enabling it for EAP systems (or not). This also applies for Windows.

    Regarding the certificate approvals, it is under investigation for getting it added to the MDM profile we provide in our product, however as this is in the early access stage at this time, it has not been updated yet.

Reply
  • As this is an EAP, the control in Central that enables SSL decryption is located under Settings, in the HTTPS/SSL decryption global settings section. There is a check mark there for enabling it for EAP systems (or not). This also applies for Windows.

    Regarding the certificate approvals, it is under investigation for getting it added to the MDM profile we provide in our product, however as this is in the early access stage at this time, it has not been updated yet.

Children
  • The text in that control is specific to Windows only.
    If you check in Overview > End[pomt Protection Dashboard > Global Settings > SSL/TLS decryption of HTTPS websites, the text is specific to Windows. There is no mention of macOS computers or that the text is inclusive of all computers.