On Email Security — Server appliances, compliance with FIPS 140-2 and Common Criteria (CC-NDCPP) certification requires that all email delivery use TLS encryption with verification mode. Verification mode requires validation of the next-hop MTA server certificate and the imported certificate authority (CA) before the TLS connection is established. If your environment does not require Common Criteria or FIPS compliance, use this command to enable opportunistic mode instead.
Syntax
[no] compliance options email-mta-tls-opportunistic
Parameters
no
Use the no form of this command to restore email delivery verification mode.
Example
The following example enables opportunistic mode:
hostname (config) # compliance options email-mta-tls-opportunistic
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 9.0.