Configure Shadow Copy Storage Server on IIS with HTTPS
SecureSync service can use a WebDav server hosted on Microsoft IIS to securely store Shadow Copy files. This section describes how to configure the Shadow Copy Storage server with HTTPS authentication.
Prerequisites
Ensure that the following requirements are met before configuring the WebDAV server:
- Operating system: Windows 10, Windows Server 2016, or later.
- Administrator privileges on the Windows server.
- A static IP address or hostname for the WebDAV server.
- Port 443 (HTTPS) and 8443 (HTTPS) available for WebDAV communication.
Note:
- If a hostname is used to access the Shadow Copy Storage server, use the same hostname when configuring the HTTPS certificate and IIS binding.
- Add host entry on EPP server machine in /etc/hosts – IPAddress hostname
-
Create the WebDAV user
-
Open Command Prompt as Administrator.
-
Run the following command:
net user Webdavuser <StrongPassword> /add -
Run the following command to verify that the user was created:
net user -
Confirm that Webdavuser is listed.
-
-
Create the WebDAV folder
- Create the following folder on the server:
C:\SecureSyncWebDAVRoot\sqepsng80 - Verify that the above folder is created successfully.
- Create the following folder on the server:
-
Provide folder permissions
-
Right-click the following folder:
C:\SecureSyncWebDAVRoot -
Select:
Properties → Security → Edit → Add -
Add the following user:
Webdavuser -
Provide the following permissions:
- Read
- Write
- Modify
- Read & Execute
-
Click Apply then click OK and click OK.
-
-
Install IIS and WebDAV [For Desktop operating system]
-
Open Control Panel.
-
Go to:
Programs → Turn Windows features on or off -
Enable and expand Internet Information Services.
-
Under Web Management Tools, enable:
- IIS Management Console
-
Under World Wide Web Services → Common HTTP Features, enable:
- Default Document
- Directory Browsing
- HTTP Errors
- Static Content
- WebDAV Publishing
-
Under World Wide Web Services → Security, enable:
- Basic Authentication
- Request Filtering
-
Click OK and wait for the installation to complete.
-
-
Install IIS and WebDAV [For Server operating system]
-
Open Server manager.
Click on add roles and features > Click on Next > Next > Next
Select web server (IIS) > Click on add features > Next > Next > Next -
Under Common HTTP Features, enable:
- Default Document
- Directory Browsing
- HTTP Errors
- Static Content
- WebDAV Publishing
-
Under → Security, enable:
- Basic Authentication
- Request Filtering
-
Click Next > Install and wait for the installation to complete > click on close.
-
-
Create the HTTPS certificate
- Open PowerShell as Administrator.
- Run the following command:
New-SelfSignedCertificate -CertStoreLocation "Cert:\LocalMachine\My" -Subject "CN=<ServerIPAddress>" -DnsName "<ServerIPAddress>" -FriendlyName "webdavsecuresync" -Type SSLServerAuthentication -KeyAlgorithm RSA -KeyLength 2048 -HashAlgorithm SHA256 -KeyExportPolicy ExportableNote: Replace
with the actual IP address or hostname of the WebDAV server. If a hostname is used during server configuration, use the same hostname in the certificate CN and DnsName fields.
-
Verify the HTTPS certificate
-
Open PowerShell.
-
Run the following command:
Get-ChildItem Cert:\LocalMachine\My | Where-Object {$_.FriendlyName -eq "webdavsecuresync"} | Select Subject,Thumbprint,DnsNameList,EnhancedKeyUsageList,FriendlyName -
Verify the following:
- Subject contains the server IP address.
- DNS Name contains the server IP address.
- Enhanced Key Usage contains Server Authentication.
- Friendly Name is webdavsecuresync.
-
-
Create the IIS website
-
Open IIS Manager → double click on available connection
-
Go to:
Sites → Add Website -
Enter the following:
- Site Name: SecureSyncWebDAV
- Physical Path: C:\SecureSyncWebDAVRoot
-
Configure the HTTPS binding as follows:
- Type: HTTPS
- IP Address:
- Port: 443
- SSL Certificate: webdavsecuresync
-
Click OK.
-
Confirm that the SecureSyncWebDAV website status is Started.
-
-
Configure authentication
- In IIS Manager, select:
SecureSyncWebDAV → Authentication - Disable Anonymous Authentication.
- Enable Basic Authentication.
- In IIS Manager, select:
-
Configure WebDAV Authoring Rules
-
In IIS Manager, select:
SecureSyncWebDAV → WebDAV Authoring Rules -
If WebDAV is disabled, click Enable WebDAV.
-
Click Add Authoring Rule.
-
Add the following user:
Webdavuser -
Allow the following permissions:
- Read
- Write
- Source
-
Click OK to save the authoring rule.
-
-
Add the .enc MIME type
-
In IIS Manager, select:
SecureSyncWebDAV → MIME Types -
Click Add.
-
Enter the following:
- File name extension: enc
- MIME type: application/octet-stream
-
Click OK.
-
-
Configure the maximum file size
- In IIS Manager, select:
SecureSyncWebDAV → Request Filtering - Click Edit Feature Settings.
- Set Maximum allowed content length to:
62914560 - Click OK.
- This setting allows files up to approximately 60 MB.
- In IIS Manager, select:
-
Allow HTTPS through Windows Firewall
-
Open Windows Defender Firewall with Advanced Security.
-
Go to:
Inbound Rules → New Rule -
Select Port and click Next.
-
Select:
- TCP
-
Enter the following under Specific local ports:
443 -
Click Next.
-
Select Allow the connection.
-
Click Next.
-
Select the required network profiles.
-
Enter the following rule name:
SecureSync WebDAV HTTPS (TCP 443) -
Click Finish.
-
-
Restart IIS
-
Open Command Prompt as Administrator.
-
Run the following command:
iisreset -
Wait until IIS restarts successful
-
-
Test the WebDAV connection
-
Open Command Prompt.
-
Run the following command:
curl.exe -vk -u Webdavuser:<StrongPassword> -X OPTIONS "https://<ServerIPAddress>/"Verify that the response contains:
HTTP/1.1 200 OK
-
-
If the connection fails, verify the following:
- IIS website status
- HTTPS certificate
- WebDAV configuration
- Webdavuser permissions
- Windows Firewall settings
Configuring the Shadow Copy Storage Server from the EPP Console
To configure the Shadow Copy Storage Server:
- Go to Configurations > Shadow Copy Storage Server.
- Specify the required configuration details.
- Click Test Connection to verify connectivity with the Shadow Copy Storage Server.
- After the connection is verified successfully, click Apply to save the configuration.
Note: Ensure that the Shadow Copy Storage Server is configured successfully before enabling Shadow Copy in a DLP policy.
Field Description
| Field | Description |
|---|---|
| Hostname / IP Address |
Specifies the hostname or IP address of the Shadow Copy Storage Server that receives files uploaded from managed endpoints. |
| Port | Specifies the communication port used by the Shadow Copy Storage Server. The default value is 443. |
| Username | Enter the user name. |
| Password | Enter the password associated with the user name. |
| File Upload Size | Select the file size from the drop-down list that can be uploaded to the Shadow Copy Storage Server. |
| Local Cache Folder | Select one of the following options for temporary file storage before uploading to the Shadow Copy Storage Server:
|
| Cache Folder Size | Enter the maximum storage size that can be used for temporary file storage. |
| File Retention Period | Select the value from the drop-down list for the the number of days you need to retain the files when the server is unavailable, subject to available cache storage. |
| Test Connection | Verifies that the Endpoint Protection server can successfully communicate with the configured Shadow Copy Storage Server. |
| Apply | Saves and applies the Shadow Copy Storage Server configuration. |
Note:
- The Shadow Copy Storage Server configuration is required for the Shadow Copy feature to function correctly.
- Files uploaded to the Shadow Copy Storage Server are encrypted using the configured File Encryption Key.
- If the Shadow Copy Storage Server is unavailable, the endpoint temporarily stores files in the configured Cache File Store Location and retries the upload based on the configured retry interval.
- Shadow Copy feature is applicable only for Windows endpoints.