Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SafeGuard Enterprise Integration

I am a vendor who is trying to integrate the Sophos product
with ours. We have a Data Discovery Suite, that crawls the cloud we provided
the customer, and other UNC or NFS mount paths, and indexes the files for
e-discovery.

The Sophos customer is just starting to deploy you product,
and we are trying to figure out how our indexing engine can de-crypt files when
it encounters them for indexing.

Is there an API for the client side we can use? They said
they will have a “GOD” key that our equipment can use.

Any other integration tools?

:26241


This thread was automatically locked due to age.
Parents
  • I can see potential issues with this already. There's the easy way and the do it yourself way. The easy way to is have a service that runs as an interactive desktop user on a dedicated machine that talks to the clients sophos server down the file that is authorized to decrypt the document, script a batch job to decrypt and copy the files to your own server. This may require a dedicated machine on their domain depending on how everything is configured, and their network is set up, maybe a VPN tunnel or if the have their SSL communication ports open you can do so over the net directly. There's probably protections built into safeguard to prevent you from just automatically importing a cert and encryption key for a specific user, I imagine there's more to it than that. A developer would have to chime in on that one.
    :26359
Reply
  • I can see potential issues with this already. There's the easy way and the do it yourself way. The easy way to is have a service that runs as an interactive desktop user on a dedicated machine that talks to the clients sophos server down the file that is authorized to decrypt the document, script a batch job to decrypt and copy the files to your own server. This may require a dedicated machine on their domain depending on how everything is configured, and their network is set up, maybe a VPN tunnel or if the have their SSL communication ports open you can do so over the net directly. There's probably protections built into safeguard to prevent you from just automatically importing a cert and encryption key for a specific user, I imagine there's more to it than that. A developer would have to chime in on that one.
    :26359
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?