fenotify preferences ssl cipher-list

Prev Next

Specifies the SSL cipher list type for event notifications.

Syntax

[no] fenotify preferences ssl cipher-list <cipher-list>

Parameters

no

Use the no form of this command to reset the cipher list type to the default. The default is compatible.

<cipher-list>

The cipher list that should be used. Specify one of the following cipher-lists.

Type

Description

original

Original Trellix cipher list (maximum compatibility)

fips

Compliant with FIPS

cc-ndcpp

Compliant with CC-NDPP

fips-and-cc-ndcpp

Compliant with both FIPS and CC-NDPP

fips-high-security

Compliant with FIPS and excludes low-security ciphers

c-ndcpp-high-security

Compliant with CC-NDPP and excludes low-security ciphers

fips-and-cc-ndcpp-high-security

Compliant with both FIPS and CC-NDPP and excludes low-security ciphers

compatible

Improved security while maintaining backward compatibility. This is the default.

Example

The following example sets the SSL cipher list to fips-high-security:

hostname (config) # fenotify preferences ssl cipher-list fips-high-security

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.2

  • Email Security — Server: Release 7.9.0

  • Endpoint Security (HX): Release 3.5.0

  • Network Security: Release 7.9.2