Restores the specified signer to the local BA signer allowlist. The local BA signer allowlist specifies the low-trust code signers that are allowlisted on the appliance.
Note
Trellix distributes a list of high-trust code signers and a list of low-trust code signers through security content downloads to the appliance. High-trust and low- trust signers own signing certificates that Trellix has associated with benign software and scripts only. A signer is categorized as high trust or low trust based on the amount of signing certificate data observed.
The local BA signer allowlist contains the Trellix-specified low-trust code signers at all times. The signer-whitelist mode <mode> changes whether this appliance-specific list is used, not its contents. To disable a specified signer in the list, use the signer-whitelist disabled <index> command. To restore specific signer in the list, use the signer-whitelist enabled <index> command.
Syntax
signer-whitelist enable <index>
Parameters
<index>
The index number of the low-trust signer you want to restore to the local BA signer allowlist. To view the index numbers of disabled signers in the local BA signer allowlist, use the show signer-whitelist disabled command.
Options
None
Examples
The following example restores the low-confidence signer with index 52 to the local BA signer whitelist:
hostname (config) # signer-whitelist enable 52
User role
Admin, Analyst
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release: 7.7