Central Management System backward compatibility
For compliance, the Central Management System management protocol for Trellix appliances earlier than 7.6 must be disabled. Earlier releases cannot achieve compliance.
Standards
FIPS 140-3, CC-NDcPP
CLI configuration command
no cmc server backward-compatible enable
CLI Show Command
show cmc server
Central Management System peer service (Central Management System only)
For compliance, the Central Management System peer service must be disabled. Although this is a secure service, it is not commonly used and therefore is not certified.
Standards
FIPS 140-3, CC-NDcPP
CLI show command
show running-config
Cryptography FIPS-compliant
OpenSSL runs in FIPS 140-3 mode (excluding out-of-scope, non management-plane components that opt out). The Linux kernel runs in FIPS 140-3 mode. In FIPS 140-3 mode, self-tests are always performed before cryptographic operations are run.
Standards
FIPS 140-3, CC-NDcPP
CLI configuration command
compliance options fips-mode-crypto enable
CLI show command
show compliance options