Usage of NTP is not permitted. The system time may be configured by authorized administrators via the “timedatectl” command of the Manager CLI.
The TLS functionality of the Trellix IPS components is pre-configured and fixed with the following behaviors:
Only TLS v1.2 is supported
The reference identifier is the IPv4 address or fully qualified domain name of the configured endpoint (matching the type used to configure the endpoint) and may be found in the SAN or CN fields of the presented certificate.
The management GUI interface on the Manager supports the following cipher suite:
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
The management GUI interface on the Manager supports the secp256r1 Elliptic Curve Extension.
Between Sensors and the Manager, the cipher suite used to perform mutual authentication are TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. The systems must use CA-signed RSA certificates with key size 2048 bits.
The syslog server interface on the Manager supports the following cipher suites:
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 as defined in RFC 5289
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 as defined in RFC 5289
The syslog server interface on the Manager supports the secp256r1 and secp384r1 Elliptic Curve Extensions.
The TOE uses HMAC-SHA-256 and HMAC-SHA-384 for TLS KDF and TLS message authentication.
Note
The Target of Evaluation (TOE) supports session resumption using session ID, which does not require any separate configuration.