email-analysis tls cipher-list

Prev Next

Configures the cipher list that is used for X.509 (TLS) certificates.

Syntax

email-analysis tls cipher-list {original | fips | cc-ndcpp | fips-and-cc-ndcpp | fips-high-security | cc-ndcpp-high-security | fips-and-cc-ndcpp high-security | compatible}

Parameters

  • original

    Original Trellix cipher list that is used for maximum compatibility.

  • fips

    A set of ciphers required by the Federal Information Processing Standard (FIPS) 140-2 certification.

  • cc-ndcpp

    A set of ciphers required by the Common Criteria Network Device Protection Profile (CC-NDPP) certification.

  • fips-and-cc-ndcpp

    A set of ciphers required by both the FIPS certification and the Common Criteria certification.

  • fips-high-security

    A set of ciphers required by FIPS certification that excludes low-security ciphers.

  • cc-ndcpp-high-security

    A set of ciphers required by the Common Criteria certification that excludes low-security ciphers.

  • fips-and-cc-ndcpp-high-security

    A set of ciphers required by both the FIPS certification and the Common Criteria certification that excludes low-security ciphers.

  • compatible

    Improved security that maintains backward compatibility.

Examples

The following example shows how to configure FIPS 140-2 compliance on the appliance.

hostname (config) # email-analysis tls cipher-list fips

The following example shows how to configure CC-NDPP compliance on the appliance.

hostname (config) # email-analysis tls cipher-list cc-ndcpp

The following example shows how to configure FIPS 140-2 and CC-NDPP compliance on the appliance.

hostname (config) # email-analysis tls cipher-list fips-and-cc-ndcp

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Before Release 7.5