show signer-whitelist mode

Prev Next

To view the mode of the local BA signer whitelist, use the show signer‑whitelist mode command.

Note

Trellix distributes a list of high-trust code signers and a list of low-trust code signers through security content downloads to the appliance. High-trust and low-trust signers own signing certificates that Trellix has associated with benign software and scripts only. A signer is categorized as high trust or low trust based on the amount of signing certificate data observed.

The local BA signer whitelist contains the Trellix-specified low-trust code signers at all times. The signer‑whitelist mode <mode> changes whether this appliance-specific list is used, not its contents. To disable a specified signer in the list, use the signer‑whitelist disabled <index> command. To restore specific signer in the list, use the signer‑whitelist enabled <index> command.

Syntax

show signer‑whitelist mode

Parameters

None

Options

None

Output fields

The following table describes the output fields for this command. Fields are listed in the approximate order in which they appear in the output.

Field

Description

BA signer mode

Mode of the local BA signer whitelist:

default—The local BA whitelist is not in effect.

insecure—The local BA whitelist is in effect. It contains the low-trust signers but

excludes signers that are explicitly disabled.

To change mode run command

Use this CLI configuration command to change the mode of the local BA signer whitelist:

● To change the mode from default to insecure:

signer-whitelist mode insecure

● To change the mode from insecure to default:

signer-whitelist mode insecure

Examples

In the following example, the local BA signer whitelist is not in effect:

hostname # show signer-whitelist mode
BA signer mode: default

To change mode run command:
signer-whitelist mode *
 

In the following example, the local BA signer whitelist is in effect. It contains low-trust signers but excludes low-trust signers that are disabled:

hostname # show signer-whitelist mode
BA signer mode: insecure

To change mode run command:
signer-whitelist mode *

User role

Admin, Analyst, fe_services, Monitor

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release: 7.7