compliance options email-mta-tls-opportunistic

Prev Next

On Email Security — Server appliances, compliance with FIPS 140-2 and Common Criteria (CC-NDCPP) certification requires that all email delivery use TLS encryption with verification mode. Verification mode requires validation of the next-hop MTA server certificate and the imported certificate authority (CA) before the TLS connection is established. If your environment does not require Common Criteria or FIPS compliance, use this command to enable opportunistic mode instead.

Syntax

[no] compliance options email-mta-tls-opportunistic

Parameters

no

Use the no form of this command to restore email delivery verification mode.

Example

The following example enables opportunistic mode:

hostname (config) # compliance options email-mta-tls-opportunistic

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 9.0.