Downloading and signing a security policy

Agent installation packages are supplied with a default security policy. You can then add your own security policy.

Before deploying a custom security policy, download it so that you can sign it to guarantee its authenticity and integrity. You then become the policy signatory.

Stormshield provides a utility that allows you to sign your policies.

The signature is based on the JWT standard. The algorithm used by default is PS256, but you can configure it.

The signature utility makes it possible to sign several policies at the same time if needed.

When the policy signatory is changed, refer to the section Modifying the signatory of a security policy.