Installing the agent for Hybrid DLP using Jamf

Use the following steps to install the macOS Forcepoint Agent using Jamf in Hybrid DLP mode.

While deploying the agent configuration profile using Jamf, you can automatically obtain the necessary permissions and accessibility to the agent that avoids complicated administrator or user confirmation dialogs. To install the agent using Jamf, do the following:

Steps

  1. Create the endpoint SSL identity.
    The following files are generated:
    • key.pem
    • server.pem
  2. Convert the server.pem file to the .der format using the following openssl command:

    openssl x509 -in server.pem -out server.der -outform DER

  3. Obtain the generate_root_ca tool from here.
  4. Run the chmod +x /Users/<username>/Downloads/generate_root_ca (replace <> with your user name) command to convert the downloaded file to .exe format, and then run the generate_root_ca.exe file in the terminal:
    The _ca.cer certificate and the fpnpd.dat file generates in the installer folder.
  5. Obtain the ca.cer and localconfig.xml files from the DLP manager in FSM, located at C:\Program Files (x86)\Websense\Data Security\client.
  6. Create an installer package for Jamf MDM deployment:
    1. Obtain the downloaded agent package and extract its contents.
    2. Create a new folder named DSEInstaller.
    3. Copy the following files(downloaded in the previous steps) into the DSEInstaller folder:
      • fpnpd.dat
      • manifest.json
      • key.pem
      • server.pem
      • WebsenseEndpoint.pkg
      • ca.cer
      • localconfig.xml
      Note: If using a custom ca.cer with multiple certificates, ensure that the cert and key for the DLP manager are placed first in the ca.cer file and any other certs are place after this.
    4. Compress the DSEInstaller folder into a zip file.
  7. Replace the ca.cer and localconfig.xml in the unzipped installer package with the ones obtained from the FSM.
    Note: If using a custom ca.cer with multiple certificates, ensure that the cert and key for the DLP manager are placed first in the ca.cer file and any other certs are place after this.
  8. Create a installer package for Jamf MDM deployment with the following files:
    • fpnpd.dat
    • manifest.json
    • key.pem
    • server.pem
    • installer.pkg
    • ca.cer
    • localconfig.xml
  9. Open Jamf Pro and in Computers > Configuration Profiles, deploy the following files through Jamf:
  10. Deploy the package in Jamf.
    The enrolled profiles will display under the Device (Managed) section in System Settings > General > Device Management in your system, and the Full Disk Access will be enabled for the following applications configured by the profiles.
    Application Path
    EndpointClassifier Library/Application Support/Websense Endpoint/EPClassifier/EndPointClassifier
    ESDaemonBundle Library/Application Support/Websense Endpoint/DLP/ESDaemonBundle.app
    AEserver System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/AE.framework/Versions/A/Support/AEServer
    FPEPAgent Library/Application Support/Websense Endpoint/Cloud/FPEPAgent
    Websense Endpoint Helper Library/Application Support/Websense Endpoint/DLP/Websense Endpoint Helper.app
    F1EHelper Library/Application Support/Websense Endpoint/F1E/F1E Helper.app
    wsdlpd Library/Application Support/Websense Endpoint/DLP/wsdlpd
    fpprotectiond Library/Application Support/Websense Endpoint/Cloud/fpprotectiond
    fpbrokerd Library/Application Support/Websense Endpoint/Cloud/fpbrokerd