Note
Release 10.0.4 is the current release after 10.0.2 for Email Security - Server.
Resolved Issues
The following issues were resolved in the Email Security - Server 10.0.4 release.
Tracking number | Summary |
|---|---|
COM-62557 | To further harden the security of our products, we have upgraded Apache HTTPd to version 2.4.62, the latest stable release. |
COM-62574 | Fixes an issue where the sensor goes into unknown state after a reboot when submission metadata streaming is enabled. |
COM-62575 | Fixes an issue where the Helix Alert notification was not displayed. |
COM-31727 | To mitigate the Terrapin Vulnerability (CVE-2023-48795), the chacha20 cipher is removed from our high-security list for non-FIPS/non-CC customers using the high-security list. Now, the Trellix platform is not vulnerable to Terrapin Vulnerability (CVE-2023-48795) with default configuration. We plan to upgrade to the latest stable version of OpenSSH in the upcoming 11.0 major release to further harden and resolve the vulnerable option related to the Terrapin Vulnerability. |
Known issues
The following issues are known in the Email Security - Server 10.0.4 release.
Tracking number | Summary |
|---|---|
COM-30656 | The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list. |
COM-30655 | During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration. Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution. |
COM-31165 | The GI settings API does not currently enforce a limit of 10 inputs for a field. |
EMPS-17820 | The downgrade of Email Security - Server to a previous release resulted in the loss of data configured on the "Advanced Rule" tab of the current release. |
EMPS-17781 | Forward email list is empty for Exchange Remediation in 'the View Email page. |
EMPS-17780 | Submitting duplicate mdsum, sha256, or URL values to allowed and blocked lists via the Web UI and CLI results in inconsistent output. |
EMPS-17729 | Remediation of emails sent to distribution lists or aliases is not supported. |
EMPS-17745 | Inconsistency output are generated when duplicate values of mdsum/sha256/url are added from Web UI and CLI for allowed and blocked list. |
EMPS-17730 | Under eAlerts > Riskware > Alert Details page, the filename field is missing. |
EMPS-17213 | On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments. |
EMPS-17700 | The EX appliance displays the following error "Application server error occurred" after running the command "system cleanup profile temp-files all". |
WEBUI-29828 | In the Email Quarantine tab, Badges option check boxes are greyed out in light mode. |
WEBUI-29818 | Introduced a loading indicator for third-party feeds within the Allow/Block lists to enhance user comprehension of data availability status. |
WEBUI-15060 | On the About > Create Log Archive page, logs do not appear after the success message. It requires a refresh of the UI to be visible. |
WEBUI-14979 | The Service Health Statistics Trend incorrectly displays date and time for weekly and monthly reports. |
WEBUI-14964 | Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI. |
Disable SAML in a Helix environment
SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.
For more information, see the Helix Integration Guide for Trellix devices.
In the Software Requirements section, see “HelixConnect Client Software Requirements”.
In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.
Upgrade support
The Trellix Email Security - Server 11.0.1 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 11.0.1 from release 9.1.0 or later.
After an upgrade to version 10.0.4, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
Created Log archive files on 9.1.x will not be preserved on upgrade to 11.0,0. Please have a backup of logs before upgrade.
Important
When you upgrade an Email Security appliance to 11.0.0, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the
Email Security — Server Edition User Guide
.
Note
After an upgrade to version 11.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.
Downloading content from the DTI offline update portal
If you download Email Security - Server 10.0.4 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
YARA rules supported versions
YARA rules support version 4.3.2.
Important
Before you upgrade an Email Security - Server appliance to the 10.0.4 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.