The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Threat Intelligence Exchange (TIE) broker configuration

Prev Next

By default, Threat Intelligence Exchange/Trellix Agent with integrated Trellix Data Exchange Layer broker uses RSA based ciphers. Follow these steps to switch from weak cipher (RSA) to strong cipher (ECDHE):

Windows based setup

  1. Navigate to <Install_Dir>\McAfee\dxlbroker and open dxlbroker.conf.defaults in a text editor.

  2. Scroll down to the section where you can edit the ciphers that the broker can be restricted to. Ensure that the broker is restricted only to the cipher - ECDHE+aRSA+AESGCM:ECDHE+aRSA+SHA384:ECDHE+aRSA+SHA256. A sample screenshot is shown below:

    Windows-dxl-broker-cipher-config.png
  3. Save the text file and close it.

  4. Restart the TIE server and the ePO service to effectively use this cipher.

Linux based setup

  1. Open dxlbroker.conf.defaults file located in /opt/Mcafee/dxlbroker/conf using a text editor.

    Note

    You need to open the file as a root user to be able to edit the file and save changes.

  2. Scroll down to the section where you can edit the ciphers that the broker can be restricted to. Ensure that the broker is restricted only to the cipher - ECDHE+aRSA+AESGCM:ECDHE+aRSA+SHA384:ECDHE+aRSA+SHA256. A sample screenshot is shown below:

    Linux-dxl-broker-cipher-config.png
  3. Save the changes.

  4. Restart the TIE server and the ePO service to effectively use this cipher.