This section lists all configuration changes required for FIPS 140-3 and CC-NDcPP compliance in Trellix release 9.0 or higher. This section describes the compliance requirements, the applicable standards, and the corresponding CLI commands. In addition, this section lists CLI show commands that display compliance changes.
Important
Compliance is not applied automatically after an upgrade. After you upgrade to Release 9.0 or later, you must check and reapply compliance.
Use the following CLI command to achieve compliance:
compliance apply standard {fips | cc-ndpp | all}
Note
After running the compliance apply standard command, you must save your changes and reboot the appliance.
You can also achieve compliance by direct configuration.
Note
The CLI commands listed in this section do not cover all configuration changes required to achieve compliance manually. The CLI commands are only for reference so that you can see the type of changes made when compliance is applied and the security limitations are imposed on the system.
When you enter the compliance apply standard command, the Trellix operating system makes a copy of the configuration database before the configuration is changed. The copy of the configuration database is named as follows:
<current_configuration_file>_pre_compliance_<date-time-stamp>
For example, if the configuration database is named initial, the Trellix operating system saves a copy under the following name:
initial_pre_compliance_20150623_134016
Use the show configuration files command to display the pre-compliance configuration database. For example:
show configuration files initial_pre_compliance_20150623_134016
Use the following command to see the compliant configuration database:
show running-config