The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Steps involved in configuring Outbound SSL Decryption

Prev Next

At a high-level, the steps to configure a Sensor to decrypt and inspect outbound SSL traffic are as follows:

  1. Procure the license to enable the outbound SSL decryption feature and add it to the Manager.

  2. Enable Outbound SSL Decryption at the domain level or on the required Sensors.

    Note

    The Sensor decrypts outbound SSL traffic only on destination TCP port 443. Outbound SSL Decryption is not supported on non-standard ports.

  3. Configure the Sensor SSL parameters for failure handling.

  4. You have an option to either import your own re-signing certificate or to use the default re-signing certificate bundled with the Manager.

    Once a client sends the request to access a secure server using SSL, the Sensor acts as a proxy between the client and the server and receives the public key and the certificate from the server. After receiving the server certificate, the Sensor uses the re-signing certificate to authenticate the session to the client and encrypt the traffic between the Sensor and the client. The expiry dates for the certificate is passed to the client. In case of expired certificates, the client generates a warning.

    You can configure your own customized certificate issued by the Certificate Authority (CA) on the Re-Signing Certificate tab.

    Note

    It is essential to export the re-signing certificate from the Manager, and import them to the client web browser's Trusted Root CA list. This helps to validate the external servers and the Sensor certificate.

    The Trusted CA Certificates tab displays the list of digital certificates issued by CAs which the Sensor uses to validate the certificates from the server. The difference between Re-Signing Certificate and Trusted CA Certificates is as follows:

    • The Re-Signing Certificate is used by the Sensor to substitute the server's certificate when establishing a session with the client. The Sensor uses this certificate on behalf of the server. In the process, the Sensor decrypts the session between the Sensor and client.

    • When the Sensor acts as a proxy for the client to the external servers, it uses the Trusted CA Certificates to validate the external servers' trustworthiness.

    Note

    Re-Signing Certificate and Trusted CA Certificates can be managed only at the root admin domain.

  5. The Sensor has a default set of trusted CA certificates. You could also import additional trusted CA certificates if any.

  6. Reboot of the Sensor is required when you enable or disable outbound SSL decryption. A full reboot of the Sensor is required.

    Any changes to the settings for outbound SSL decryption requires a configuration deployment to the Sensor. For example, any change to the re-signing certificate or failure handling, the configuration update has to be deployed to the Sensor. You can deploy the configuration update for a Sensor from Devices → <Admin Domain Name> → Devices → <Device Name> → Deploy Pending Changes.

    Various fault messages related to SSL decryption may also be raised on the Faults tab under Logs page in the Manager. For example, an imported re-signing certificate might have become invalid. This causes client browser to raise a certificate error.

    For more information on fault messages, see Trellix Intrusion Prevention System Product Guide.