Hello,
You all know that there is a way to gain access to HTTPS decrypted data via fw ctl set ... interface.
Now, we need to have second firewall admin with expert access, this cannot be avoided for many reasons.
However, because of the EU GDPR requirements he/she must not be able to gain any access to employees personal data because he is not authorized for that.
Certain categories (Health, Financial) are already bypassed and I am thinking to restrict that admin access to modify HTTPS Inspection policy but I am not sure that is good enough first because false categorization may happen and second it kind of limits that admin in his tasks to modify policy should another urgent reason arises.
So, is there any way to restrict access to fw ctl set ... for an admin with expert access or otherwise how do you recommend to handle such situation?