To view the mode of the local BA signer whitelist, use the show signer‑whitelist mode command.
Note
Trellix distributes a list of high-trust code signers and a list of low-trust code signers through security content downloads to the appliance. High-trust and low-trust signers own signing certificates that Trellix has associated with benign software and scripts only. A signer is categorized as high trust or low trust based on the amount of signing certificate data observed.
The local BA signer whitelist contains the Trellix-specified low-trust code signers at all times. The signer‑whitelist mode <mode> changes whether this appliance-specific list is used, not its contents. To disable a specified signer in the list, use the signer‑whitelist disabled <index> command. To restore specific signer in the list, use the signer‑whitelist enabled <index> command.
Syntax
show signer‑whitelist mode
Parameters
None
Options
None
Output fields
The following table describes the output fields for this command. Fields are listed in the approximate order in which they appear in the output.
Field | Description |
|---|---|
BA signer mode | Mode of the local BA signer whitelist: ● default—The local BA whitelist is not in effect. ● insecure—The local BA whitelist is in effect. It contains the low-trust signers but excludes signers that are explicitly disabled. |
To change mode run command | Use this CLI configuration command to change the mode of the local BA signer whitelist: ● To change the mode from default to insecure:
● To change the mode from insecure to default:
|
Examples
In the following example, the local BA signer whitelist is not in effect:
hostname # show signer-whitelist mode BA signer mode: default To change mode run command: signer-whitelist mode *
In the following example, the local BA signer whitelist is in effect. It contains low-trust signers but excludes low-trust signers that are disabled:
hostname # show signer-whitelist mode BA signer mode: insecure To change mode run command: signer-whitelist mode *
User role
Admin, Analyst, fe_services, Monitor
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release: 7.7