TACACS+ authentication and accounting
For compliance, TACACS+ authentication and accounting must be disabled.
CLI configuration commands
aaa authentication login default {ldap | local}
no aaa accounting changes default stop-only tacacs+
Standards
FIPS 140-3, CC-NDcPP
CLI show command
show aaa
TLS verification mode and opportunistic mode
On Email Security — Server appliances, compliance with Common Criteria (CC-NDCPP) certification requires verification mode, in which all email delivery and receipts are TLS-encrypted with certificate verification. If your environment does not require Common Criteria compliance, you can enable opportunistic mode
CLI configuration commands
email-analysis tls delivery <mode>
compliance options email-mta-tls-opportunistic
CLI show command
show compliance options