To enable the configuration deployment without requiring user approval of the network extension, create the following payload.
Procedure
- Set the Filter Name:
VMware Carbon Black Cloud Network Extension Filter.
- Set the Identifier:
com.vmware.carbonblack.cloud.se-agent
- Set the Socket Filter Bundle Identifier:
com.vmware.carbonblack.cloud.se-agent.extension
- Set the Socket Filter Designated Requirement:
identifier "com.vmware.carbonblack.cloud.se-agent.extension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "7AGZNQ2S2T"
- Set the Network Filter Bundle Identifier:
com.vmware.carbonblack.cloud.se-agent.extension
- Set the Network Filter Designated Requirement:
identifier "com.vmware.carbonblack.cloud.se-agent.extension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "7AGZNQ2S2T"
- Save the configuration profile.
Example: