The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Protocol features in the certified evaluated configuration

Prev Next

Usage of NTP is not permitted. The system time may be configured by authorized administrators via the “timedatectl” command of the Manager CLI.

The TLS functionality of the Trellix IPS components is pre-configured and fixed with the following behaviors:

  • Only TLS v1.2 is supported

  • The reference identifier is the IPv4 address or fully qualified domain name of the configured endpoint (matching the type used to configure the endpoint) and may be found in the SAN or CN fields of the presented certificate.

  • The management GUI interface on the Manager supports the following cipher suite:

    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

  • The management GUI interface on the Manager supports the secp256r1 Elliptic Curve Extension.

  • Between Sensors and the Manager, the cipher suite used to perform mutual authentication are TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. The systems must use CA-signed RSA certificates with key size 2048 bits.

  • The syslog server interface on the Manager supports the following cipher suites:

    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289

    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289

  • The syslog server interface on the Manager supports the secp256r1 and secp384r1 Elliptic Curve Extensions.

  • The TOE uses HMAC-SHA-256 and HMAC-SHA-384 for TLS KDF and TLS message authentication.

    Note

    The Target of Evaluation (TOE) supports session resumption using session ID, which does not require any separate configuration.