signer-allowlist mode <mode>

Prev Next

Disables or enables the use of the local BA signer allowlist. The local BA signer allowlist specifies the low-trust code signers that are allowlisted on the appliance.

Note

Trellix distributes a list of high-trust code signers and a list of low-trust code signers through security content downloads to the appliance. High-trust and low- trust signers own signing certificates that Trellix has associated with benign software and scripts only. A signer is categorized as high trust or low trust based on the amount of signing certificate data observed.

The local BA signer allowlist contains the Trellix-specified low-trust code signers at all times. The signer‑whitelist mode <mode> changes whether this appliance-specific list is used, not its contents. To disable a specified signer in the list, use the signer‑whitelist disabled <index> command. To restore specific signer in the list, use the signer‑whitelist enabled <index> command.

Syntax

signer-whitelist mode <mode>

Parameters

<mode>

Specify whether the local BA allowlist is in effect:

  • default—The local BA allowlist is not in effect. Only the high-trust signers are allowlisted.

  • insecure—The local BA signer allowlist is in effect. It contains the low-trust signers that have not been disabled.

Options

None

Examples

The following example changes the local BA signer allowlist mode to default:

hostname (config) # signer-whitelist mode default

The following example changes the local BA signer allowlist mode to insecure:

hostname (config) # signer-whitelist mode insecure

User role

Admin, Analyst

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release: 7.7