The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Inspection of SSL/TLS traffic

Prev Next

Several web and cloud servers use Secure Socket Layer (SSL) or Transport Layer Security (TLS) to encrypt traffic these days. Using SSL creates a secure environment for clients to access web content and cloud content. This gives the cyber criminals a window to get into a secure company network.

As web content increasingly becomes encrypted with SSL/TLS, so does the need to inspect and analyze encrypted traffic. Trellix IPS's Sensors are equipped to decrypt SSL packets for inspection and respond in cases of an attack. The Sensor also has the ability to decrypt traffic in both directions.

For outbound SSL and inbound SSL, while establishing an SSL connection, the client and the server establish a handshake to determine the SSL version, compression method, and cipher suite. Once these details are ascertained, the server sends the public key and its certificate to the client to validate. The client browser checks for the following details while validating the certificate:

  • Expiry date of the certificate — While issuing the certificate, the Certificate Authority (CA) such as Verizon or Comodo adds a date in the certificate after which it becomes invalid.

  • Format of the certificate — Different file formats are used for certificates based on how they are encoded. The most common format is Public-Key Cryptography Standards (PKCS) which is published by RSA Laboratories. For Inbound and outbound SSL Decryption, Trellix IPS supports the PKCS12 format. The private key must be a part of the PKCS12 file.

  • Authenticity of the certificate — The client browser uses the public key of the certificate to decrypt and authenticate the certificate.

Each web browser has a list of trusted certificates. When a client receives the certificate from the server, the browser compares the certificate with the trusted list. If the certificate is trusted, the connection is established between the client and the server. If a match is not found, the browser displays a error message. For example, in Mozilla Firefox, you get an error message that says Your connection is not secure.

For increased security, you can restrict access to the Manager by using secure ciphers like TLS 1.2. By default, Manager allows connections from all ciphers. You can remove the less secure ciphers from the Manager configuration thereby restricting access to the Manager. For example, you can remove Manager access using TLS1.0 and provide access only through TLS 1.2. This restricts access to the Manager. To edit the cipher list in the Manager configuration, go to C:\Program Files\Trellix\IPS Manager\App\apache-tomcat\conf.