T

Prev Next

TACACS+ authentication and accounting

For compliance, TACACS+ authentication and accounting must be disabled.

CLI configuration commands

aaa authentication login default {ldap | local}

no aaa accounting changes default stop-only tacacs+

Standards

FIPS 140-3, CC-NDcPP

CLI show command

show aaa

TLS verification mode and opportunistic mode

On Email Security — Server appliances, compliance with Common Criteria (CC-NDCPP) certification requires verification mode, in which all email delivery and receipts are TLS-encrypted with certificate verification. If your environment does not require Common Criteria compliance, you can enable opportunistic mode

CLI configuration commands

email-analysis tls delivery <mode>

compliance options email-mta-tls-opportunistic

CLI show command

show compliance options