Downloading and signing a security policy

Agent installation packages are supplied with a default security policy. You can then add your own security policy.

Before deploying a custom security policy, you must download it for it to be signed by a signatory account, to guarantee its authenticity and integrity.

Stormshield provides a utility that allows you to sign your policies.

The signature is based on the JWT standard. The default algorithm used is RSASSA-PSS SHA256 (PS256), but you can configure this.

The signature utility makes it possible to sign several policies at the same time if needed.

When the policy signatory is changed, refer to the section Modifying the signatory of a security policy.