Configuring the encrypted connections scan settings

To configure the encrypted connections scan settings:

  1. In the main application window, click the Settings button.
  2. In the left part of the window, in the General settings section, select the Network settings subsection.

    The network settings are displayed in the right part of the window.

  3. In the right part of the window, in the Encrypted connections scan section, click the Advanced settings button.

    The Advanced settings window opens.

  4. In the When visiting a domain with an untrusted certificate drop-down list, select one of the following items:
    • Allow If this item is selected, when visiting a domain with an untrusted certificate, Kaspersky Endpoint Security allows the network connection.

      When opening a domain with an untrusted certificate in a browser, Kaspersky Endpoint Security displays an HTML page showing a warning and the reason why visiting that domain is not recommended. A user can click the link from the HTML warning page to obtain access to the requested web resource. After following this link, during the next hour Kaspersky Endpoint Security will not display warnings about an untrusted certificate when visiting other resources on this same domain.

    • Block. If this item is selected, when visiting a domain with an untrusted certificate, Kaspersky Endpoint Security blocks the network connection established when visiting this domain.

      When opening a domain with an untrusted certificate in a browser, Kaspersky Endpoint Security displays an HTML page showing the reason why that domain is blocked.

  5. In the When secure connection scan errors occur drop-down list, select one of the following items:
    • Break connection. If this item is selected, when an encrypted connection scan error occurs, Kaspersky Endpoint Security blocks the network connection.
    • Add domain to exclusions. If this item is selected, when an encrypted connection scan error occurs, Kaspersky Endpoint Security adds the domain that resulted in the error to the list of domains with scan errors and does not monitor encrypted network traffic when this domain is visited.

      Click the Domains with scan errors link to open the Domains with scan errors window that lists the domains added to exclusions when an encrypted connection scan error occurred.

      The Domains with scan errors link is available if the Add domain to exclusions item is selected.

      When you select the Break connection item in the When secure connection scan errors occur drop-down list, Kaspersky Endpoint Security deletes all exclusions listed in the Domains with scan errors window.

  6. Select the Block SSL 2.0 connections check box if you want Kaspersky Endpoint Security to block network connections that are established over the SSL 2.0 protocol.

    Clear the Block SSL 2.0 connections check box if you do not want Kaspersky Endpoint Security to block network connections that are established over the SSL 2.0 protocol, and do not want the application to monitor network traffic transmitted over these connections.

    It is not recommended to use the SSL 2.0 protocol because it has shortcomings that affect secure data transmission.

  7. Select the Decrypt secure connections with EV certificate check box if you want Kaspersky Endpoint Security to decrypt and monitor network traffic transmitted over encrypted connections that are established in the browser using an EV certificate.

    Clear the Decrypt secure connections with EV certificate check box if you do not want Kaspersky Endpoint Security to decrypt and monitor network traffic transmitted over encrypted connections that are established in the browser using an EV certificate.

  8. Click OK.
  9. To save changes, click the Save button.
Page top