Changes required by compliance

Prev Next

This section lists all configuration changes required for FIPS 140-3 and CC-NDcPP compliance in Trellix release 9.0 or higher. This section describes the compliance requirements, the applicable standards, and the corresponding CLI commands. In addition, this section lists CLI show commands that display compliance changes.

Important

Compliance is not applied automatically after an upgrade. After you upgrade to Release 9.0 or later, you must check and reapply compliance.

Use the following CLI command to achieve compliance:

compliance apply standard {fips | cc-ndpp | all}

Note

After running the compliance apply standard command, you must save your changes and reboot the appliance.

You can also achieve compliance by direct configuration.

Note

The CLI commands listed in this section do not cover all configuration changes required to achieve compliance manually. The CLI commands are only for reference so that you can see the type of changes made when compliance is applied and the security limitations are imposed on the system.

When you enter the compliance apply standard command, the Trellix operating system makes a copy of the configuration database before the configuration is changed. The copy of the configuration database is named as follows:

<current_configuration_file>_pre_compliance_<date-time-stamp>

For example, if the configuration database is named initial, the Trellix operating system saves a copy under the following name:

initial_pre_compliance_20150623_134016

Use the show configuration files command to display the pre-compliance configuration database. For example:

show configuration files initial_pre_compliance_20150623_134016

Use the following command to see the compliant configuration database:

show running-config