McAfee EPOCDE-AA-BA Product Guide - Page 188

Supported package types, Package signing and security, Package type, Description, Origination

Page 188 highlights

16 Using tasks to manage products and systems Deployment packages for products and updates These package types can be checked in to the master repository with pull tasks, or manually. Supported package types Package type SuperDAT (SDAT.exe) files File type: SDAT.exe Supplemental detection definition (ExtraDAT) files File type: ExtraDAT Product deployment and update packages File type: zip Agent language packages File type: zip Description Origination The SuperDAT files contain both DAT and engine files in one update package. If bandwidth is a concern, McAfee recommends updating DAT and engine files separately. McAfee website. Download and check SuperDAT files in to the master repository manually. The ExtraDAT files address one or more specific threats that have appeared since the last DAT file was posted. If the threat has a high severity, distribute the ExtraDAT immediately, rather than wait until that signature is added to the next DAT file. ExtraDAT files are from the McAfee website. You can distribute them through ePolicy Orchestrator. Pull tasks do not retrieve ExtraDAT files. McAfee website. Download and check supplemental DAT files in to the master repository manually. A product deployment package contains the installation software of a McAfee product. Product CD or downloaded product zip file. Check product deployment packages in to the master repository manually. For specific locations, see the documentation for that product. An agent language package contains files necessary to display agent information in a local language. Master repository - Checked in at installation. For future versions of the agent, you must check agent language packages into the master repository manually. Package signing and security All packages created and distributed by McAfee are signed with a key pair using the DSA (Digital Signature Algorithm) signature verification system, and are encrypted using 168-bit 3DES encryption. A key is used to encrypt or decrypt sensitive data. You are notified when you check in packages that are not signed by McAfee. If you are confident of the content and validity of the package, continue with the check-in process. These packages are secured in the same manner described above, but are signed by ePolicy Orchestrator when they are checked in. Digital signatures guarantee that packages originated from McAfee or were checked in by you, and that they have not been tampered with or corrupted. The agent only trusts package files signed by ePolicy Orchestrator or McAfee. This protects your network from receiving packages from unsigned or untrusted sources. 188 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

These package types can be checked in to the master repository with pull tasks, or manually.
Supported package types
Package type
Description
Origination
SuperDAT (SDAT.exe)
files
File type: SDAT.exe
The SuperDAT files contain both DAT and
engine files in one update package. If
bandwidth is a concern, McAfee
recommends updating DAT and engine
files separately.
McAfee website. Download and
check SuperDAT files in to the
master repository manually.
Supplemental
detection definition
(ExtraDAT) files
File type: ExtraDAT
The ExtraDAT files address one or more
specific threats that have appeared since
the last DAT file was posted. If the threat
has a high severity, distribute the
ExtraDAT immediately, rather than wait
until that signature is added to the next
DAT file. ExtraDAT files are from the
McAfee website. You can distribute them
through ePolicy Orchestrator. Pull tasks
do not retrieve ExtraDAT files.
McAfee website. Download and
check supplemental DAT files in
to the master repository manually.
Product deployment
and update packages
File type: zip
A product deployment package contains
the installation software of a McAfee
product.
Product CD or downloaded
product zip file. Check product
deployment packages in to the
master repository manually. For
specific locations, see the
documentation for that product.
Agent language
packages
File type: zip
An agent language package contains files
necessary to display agent information in
a local language.
Master repository — Checked in
at installation. For future versions
of the agent, you must check
agent language packages into the
master repository manually.
Package signing and security
All packages created and distributed by McAfee are signed with a key pair using the DSA (Digital
Signature Algorithm) signature verification system, and are encrypted using 168-bit 3DES encryption.
A key is used to encrypt or decrypt sensitive data.
You are notified when you check in packages that are not signed by McAfee. If you are confident of the
content and validity of the package, continue with the check-in process. These packages are secured
in the same manner described above, but are signed by ePolicy Orchestrator when they are checked in.
Digital signatures guarantee that packages originated from McAfee or were checked in by you, and
that they have not been tampered with or corrupted. The agent only trusts package files signed by
ePolicy Orchestrator or McAfee. This protects your network from receiving packages from unsigned or
untrusted sources.
16
Using tasks to manage products and systems
Deployment packages for products and updates
188
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide