- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- HARMONY ENDPOINT DIGITAL SIGNATURED FILES
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HARMONY ENDPOINT DIGITAL SIGNATURED FILES
Hello,
I have noticed that Treat Extraction removes digital signatures from pdf documents (.cleaned) and makes them being invalid.
In Threat Prevention Policy -> Web & Files Protection -> Advanced Settings -> Download Protection -> Extract potential malicious elements -> Elements to Extract, everything is checked.
Is there any chance digital signatures fall under one of these categories and after unchecking them, digital signatures are not removed from Threat Extracted pdf files?
I know that I can only emulate these files or just exclude the relevant URLs, but it is not suittable in my case.
Regards,
Ioannis
- Labels:
-
Threat Extraction
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
As informed from TAC, we excluded the relevant URLs from Threat Emulation and the problem is solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I do not think it si possible. However, there should be an option to request an original file.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If we left the digital signature in there, it would be invalid since the file served to the user is different from it's original and the signature is based on the file contents.
This means we would have to generate a new digital signature for the cleaned file.
This is probably an RFE and if this is a hard requirement, I suggest engaging with your local Check Point office.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
As informed from TAC, we excluded the relevant URLs from Threat Emulation and the problem is solved.
