This URL updates the SSL configuration at the domain level.
Resource URL
PUT /domain/<domainId>/sslconfiguration
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain id | Number | Yes |
Payload Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Inherit settings from parent domain. | Boolean | Yes |
| SSL state. Values can be:
| String | Yes |
| Anticipated inbound SSL traffic usage. Values can be:
| String | Yes |
| The maximum amount of time a Sensor will keep an outbound SSL flow open when no data is seen on the Sensor. | Number | Yes |
| Include decrypted packets while packet capture. | Boolean | Yes |
| DH support | Boolean | |
| Maximum concurrent connections allowed between a Trellix Agent and a Sensor. The value can range from 1 to 1024. | Number | Yes |
| IPv4 CIDR blocks | Object | Yes |
| IPv6 CIDR blocks | Object | Yes |
| Failure handling | Object | Yes |
Details of permittedIPv4CIDRBlocks and permittedIPv6CIDRBlocks.
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Action for the CIDR. The values can be "delete" for deletion. | Number | No |
| CIDR block | String | Yes |
Details of failureHandling.
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Action to take if the target web server's certificate is not on the Sensor's trusted CA list. Used only in case of outbound SSL. The values can be:
| String | Yes |
Response Parameters
Following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Set to 1 if the operation was successful | Number |
Example
Request
PUT https://<NSM_IP>/sdkapi/domain/0/sslconfiguration
Payload
{
"inheritSettings": false,
"decryptionState": "INBOUND",
"anticipatedSSLTrafficUsage": "HEAVY",
"sslInactivityTimeoutInMinutes": 1,
"enableDhSupport": true,
"maxConcurrent": 210,
"permittedIPv4CIDRBlocks": [{"cidr":"10.1.1.0/23"}],
"permittedIPv6CIDRBlocks": [{"cidr":"2001:DB9::1/122"}],
"decryptedFlow": 20,
"includeDecryptedPCAPS": false
}
Response
{
"status": 1
}
Error Information
Following error codes are returned by this URL:
S.No | HTTP Error Code | SDK API errorId | SDK API errorMessage |
|---|---|---|---|
1 | 404 | 1105 | Invalid domain |
2 | 500 | 1001 | Internal error |