The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Steps involved in configuring SSL decryption

Prev Next

At a high-level the following are the steps to configure a Sensor to decrypt and inspect SSL traffic:

  1. Enable SSL decryption on the required Sensors and configure Sensor SSL parameters.
  2. SSL decryption is by two methods:
    1. For Agent based method — Select the Enable Diffie-Helman Support checkbox to enable decryption. In the Agent based method, install the Agent on the web servers to be protected.

      Note

      Agent based method is not supported for AWS, Azure, and OCI cloud platforms.

    2. For the Known key method — Import the private SSL certificates of the corresponding web servers into the Manager. The Sensors subsequently download these certificates from the Manager.

Note

  • Various fault messages are raised in the Manager related to SSL decryption. For example, an imported SSL certificate might have become invalid or you might have modified SSL configuration settings that requires a Sensor reboot. All these fault messages are explained in detail in the System fault messages.
  • After you install the Agent on a virtual machine, the VM will auto reboot.