Note
Release 11.0.1 is the current release after 11.0.0 for File Protect.
New features and changes
This section describes new features or enhancements in the File Protect 11.0.1 release.
FLOSS artifacts updates on Alerts page
On the Alerts page, FLOSS will be shown in the Artifact column whether it is enabled or not. FLOSS artifacts are disabled by default. Disabled FLOSS artifacts will not be displayed in the following situations:
On expanding the alert details
Inside a triage bundle
On downloading artifacts from the API
Use the following CLIs to configure FLOSS artifacts.
[no] analysis artifact floss enable: Enable or disable FLOSS artifactshow analysis artifact floss: Display FLOSS artifact
Configuring DUA object size
You can now configure the DUA downloadable object size using the CLI,
analysis file max-size dua-file <size>. The default limit of 128 MB has been removed. You can select a size between 1 to 1024 MB. You can also perform static analysis on the partially downloaded objects.Bulk configuration on Health Services tab
In the Health Services tab, you can select the newly added check box to enable or disable all services/notifications in bulk.
LDAP client update
The LDAP client now supports the automatic fetching of Certificate Revocation Lists (CRLs), along with existing manual updates feature.
Synchronization with TAXII
The TAXII client within the appliance is now correctly routed through the Fenet proxy (if configured), allowing for successful synchronization with the TAXII server.
Enhancements
This section describes the enhancements implemented in the Trellix File Protect release 11.0.1.
TLS 1.3 Support for Appliance Management
The appliance base components have been upgraded to fully support TLS 1.3 for management protocols, including the web management interface. This enhancement enforces access rules when Web Client Certificate Authentication is enabled, client certificates are now required for all WSAPI calls, and there is no fallback to other authentication methods for Web Portal access.
Support local time streaming for events
The
streamingdservice now supports the configuration of event timestamps to reflect the local time zone set on the appliance, rather than the default Coordinated Universal Time (UTC).datastreaming submission local-timestamp enable- Enable the streaming of event timestamps in the appliance's local time zone.no datastreaming submission local-timestamp enable- Revert the streaming of event timestamps back to the default UTC format.show datastreaming submission- View the status of this new "Streaming in Local Time" feature, use existing CLI.
Enhanced data streaming configuration guidance for TLS Syslog
You can now follow updated guidance for configuring secure (SSL/TLS) syslog for data streaming. This guide provides the specific settings required to ensure your TLS syslog server (typically on port 6514) is compatible with the standard RFC 5424 format.
datastreaming configuration protocol rsyslog consumers <consumer-name> output-type Syslog-TLS: Specifies that the data stream consumer will use the secure Syslog-TLS protocol for output.datastreaming configuration protocol rsyslog consumers <consumer-name> msg-style ietf: Ensures the syslog messages are formatted according to the IETF standard (RFC 5424).
The CLI,
datastreaming configuration protocol rsyslog consumers <consumer-name> ssl ca-list <option>, now has updated CA list options:builtin-only: no supplemental list, can only use built-in one.default-ca-list: default supplemental CA certificate list.undefined: Implements dynamic logic to determine inclusion/exclusion automatically.based on context: For example, configuration defaults to default-ca-list when SSL is disabled.
Enhanced certificate authority (CA) list configuration for TLS Syslog
You can now use enhanced configuration options for managing Certificate Authority (CA) lists when setting up secure (SSL/TLS) rsyslog consumers. This update provides greater control and introduces a dynamic default behavior for including CA certificates.
Log manager updates
The Upload option on the Log Manager page used to upload archived files has been removed.
Modified CLIs
The
configuration jumpstartcommand now supports both pure IPv6 and dual-stack (IPv4/IPv6) configurations, enabling successful deployment in IPv6-only environments.The output for
show analysis confignow displays the maximum size of a DUA downloadable object.
Resolved issues
The following issues were resolved in the File Protect 11.0.1 release.
Tracking number | Summary |
|---|---|
COM-62386 | Fixes the issue where the appliance included a version of the python3 idna software module associated with CVE-2024-3651. The module is now updated to a non-vulnerable version. This proactively addresses the potential vulnerability even though the appliance did not use the specific vulnerable function. |
COM-63130 | Removed the diffie-hellman-group14-sha1 Key Exchange (KEX) cipher from our supported CC and FIPS cipher lists. |
COM-63373 | Fixed the vulnerability CVE-2022-27406 issue by updating the FreeType library |
COM-63528 | Resolved an issue where the File Protect appliance's management interface (ether1) was incorrectly attempting to establish connections for sandbox analysis. |
FMPS-2963 | Fixes an issue of releasing multiple quarantined files at once. |
FMPS-2964 | Fixes an issue of fe-quarantined file still appearing at the source even after performing a scan and releasing any existing quarantined file. |
WEBUI-14964 | Fixes an issue in the 3rd Party Feeds tab where any file with STIX type could be uploaded. Now an error occurs on uploading invalid files. |
WEBUI-30013 | Addresses remote code execution vulnerability in the web UI. An attacker could exploit this vulnerability to execute commands on the underlying operating system by viewing malware artifact details in the Alerts view. |
Known Issues
The following issues are known in the File Protect 11.0.1 release.
Tracking number | Summary |
|---|---|
COM-63593 | Upgrading to version 11.0.1 from version 9.1.5 fails to migrate custom MD5 and SHA-256 blacklisted entries. |
COM-63635 | Compliance mode appliances are logging too much noise with SSL_ERROR_WANT_READ informational status. |
COM-63684 | FLOSS artifact will be displayed in the Artifact column on eAlerts page whether the FLOSS is disabled or not. |
WEBUI-30212 | When certificate authentication is enabled, deleted certificates reappear after the page is reloaded. |
Additional upgrade information
The Trellix File Protect 11.0.1 release requires a reboot for the update to take effect. You can upgrade your FX appliance to 11.0.1 from release 9.0.0 or later.
After an upgrade to version 11.0.1, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
After an upgrade to version 11.0.1, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.
Created log archive files will not be preserved on upgrade to 11.0.1. Please have a backup of logs before the upgrade.
Note
After an upgrade to version 11.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, Download the security content bundle.
Important
When upgrading an X500 FX running in FIPS/CC compliance mode to version 11.0.1, you must reapply the compliance mode immediately after the upgrade. Use the CLI command compliance apply standard <standard name> and save the configuration using the CLI write memory.
After reapplying compliance mode, ensure that any necessary compliance options overrides are reasserted as needed. In rare instances, the appliance may become unresponsive before compliance can be applied. If this occurs, the appliance may need to be power cycled.
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.1.
Downloading content from the DTI offline update portal
If you download File Protect 11.0.1 security content from the DTI Offline Update Portal, use the SCNET-9.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
YARA rules supported versions
YARA rules support version 4.5.0.
Important
Before you upgrade an File Protect appliance to the 11.0.1 release, modify any custom YARA rules to YARA 4.5.0. For details about YARA 4.5.0, see YARA's Documentation, Release 4.5.0 by Victor Alvarez.