Shield Deployment & Certificates
Deploy the EndDefend Shield connector on your endpoints and install the latest trusted CA Certificates for secure SSL inspection.
You must be a registered user of EndDefend before deploying these tools. The connectors require an active tenant to route traffic correctly.
Download Shield Connectors
Install the lightweight endpoint connector for your operating system.
macOS Connector
Compatible with macOS Ventura (13.0) and later. Apple Silicon (M1/M2/M3) natively supported.
v2.1.4 (Universal Binary) - 45MB
Windows Connector
Compatible with Windows 10 and Windows 11. Requires Administrator privileges for install.
v2.1.4 (64-bit Installer) - 38MB
Install CA Certificates
Required to prevent SSL warnings and enable deep packet inspection.
EndDefend Root CA
Updated: September 2026. Valid until 2036.
Installation Instructions:
macOS
- Double click the downloaded
.pemfile. - Keychain Access will open. Select the System keychain.
- Double click the imported certificate.
- Expand Trust, and change "When using this certificate" to Always Trust.
Windows
- Double click the downloaded
.crtfile. - Click Install Certificate...
- Select Local Machine and click Next.
- Place all certificates in the following store: Trusted Root Certification Authorities.
Network Configuration
Configure your system or router to forward traffic to the Shield Gateway.
Gateway Settings
Proxy Hostname
gateway.enddefend.com
Port
8081
Once the Shield Connector is installed and the CA certificates are trusted, configure your OS-level proxy settings to route HTTP and HTTPS traffic through the gateway above.
Traffic mapped to this gateway will be deep-inspected according to your tenant's active DLP policies and SaaS blocking rules.
