Skip to main content

Enforcing policies for security settings in your enterprise

You can enforce policies to manage security settings in your enterprise's organizations, or allow policies to be set in each organization.

Who can use this feature

Enterprise owners can enforce policies for security settings in an enterprise.

About policies for security settings in your enterprise

You can enforce policies to control the security settings for organizations owned by your enterprise on GitHub AE. By default, organization owners can manage security settings. For more information, see "Keeping your organization secure."

Managing allowed IP addresses for organizations in your enterprise

You can restrict network traffic to your enterprise on GitHub AE. For more information, see "Restricting network traffic to your enterprise."

Managing SSH certificate authorities for your enterprise

You can use a SSH certificate authorities (CA) to allow members of any organization owned by your enterprise to access that organization's repositories using SSH certificates you provide. 您可以要求成员使用 SSH 证书访问组织资源,除非 SSH 已在仓库中禁用。 For more information, see "About SSH certificate authorities."

在颁发每个客户端证书时,必须包含扩展,以指定证书用于哪个 GitHub AE 用户。 有关详细信息,请参阅“关于 SSH 证书颁发机构”。

Adding an SSH certificate authority

If you require SSH certificates for your enterprise, enterprise members should use a special URL for Git operations over SSH. For more information, see "About SSH certificate authorities."

  1. 在 GitHub AE 的右上角,单击你的个人资料照片,然后单击“企业设置”。 GitHub AE 上个人资料照片下拉菜单中的“企业设置”

  2. 在企业帐户侧边栏中,单击 “设置”。 企业帐户侧边栏中的“设置”选项卡

  3. In the left sidebar, click Security. Security tab in the enterprise account settings sidebar

  4. 在“SSH 证书颁发机构”右侧,单击“新建 CA”。 “新建 CA”按钮

  5. 在“Key(密钥)”下,粘贴您的公共 SSH 密钥。 用于添加 CA 的密钥字段

  6. 单击“添加 CA”。

  7. (可选)若要要求成员使用 SSH 证书,请选择“需要 SSH 证书”,然后单击“保存” 。 “需要 SSH 证书”复选框和“保存”按钮

Deleting an SSH certificate authority

Deleting a CA cannot be undone. If you want to use the same CA in the future, you'll need to upload the CA again.

  1. 在 GitHub AE 的右上角,单击你的个人资料照片,然后单击“企业设置”。 GitHub AE 上个人资料照片下拉菜单中的“企业设置”

  2. 在企业帐户侧边栏中,单击 “设置”。 企业帐户侧边栏中的“设置”选项卡

  3. In the left sidebar, click Security. Security tab in the enterprise account settings sidebar

  4. 在“SSH 证书颁发机构”下,在要删除的 CA 右侧,单击“删除”。 “删除”按钮

  5. 阅读警告,然后单击“我了解,请删除此 CA”。 删除确认按钮